CVE Tools

Description

NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request.

In plain language

AI Worth attention

CVE-2016-5677 is a hardcoded password issue in some NUUO/NETGEAR surveillance devices that lets an attacker remotely pull sensitive information without logging in; if you run one of these devices on the internet, you should act.

Executive summary

CVE-2016-5677 is a remotely reachable information disclosure issue caused by a hidden account with a fixed hardcoded password, allowing an attacker to retrieve confidential data via a specific __nvr_status___.php request without authentication.

If affected, business impact
Confidential footage or device info leakPrivacy and compliance riskAccount/device exposure to attackersIncreased odds of later attacks

What to do now

  1. Check whether your business uses NUUO NVRmini 2, NUUO NVRsolo, or NETGEAR ReadyNAS Surveillance, and confirm your exact software/device version is within the affected ranges (NUUO NVRmini 2 1.7.5–3.0.0, NUUO NVRsolo 1.0.0–3.0.0, ReadyNAS Surveillance 1.1.1–1.4.1).
  2. Verify the device is reachable from outside your local network (for example, whether port-forwarding or a public IP/remote access exposes it to the internet).
  3. Since no vendor patch version is listed for this CVE, immediately reduce exposure: restrict access to the device to your internal network only, and remove any unnecessary internet-facing access paths (e.g., remove port forwards / disable remote admin features that publish the endpoint).
  4. If you cannot fully restrict external access, plan an upgrade or replacement using the vendor’s currently supported firmware for your exact product line, and document the change.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:NA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:NIntegrity
None
A:NAvailability
None

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Collection
View detailed technique mapping

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2016-5677 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store