Description
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request.
In plain language
AI Worth attentionCVE-2016-5677 is a hardcoded password issue in some NUUO/NETGEAR surveillance devices that lets an attacker remotely pull sensitive information without logging in; if you run one of these devices on the internet, you should act.
CVE-2016-5677 is a remotely reachable information disclosure issue caused by a hidden account with a fixed hardcoded password, allowing an attacker to retrieve confidential data via a specific __nvr_status___.php request without authentication.
What to do now
- Check whether your business uses NUUO NVRmini 2, NUUO NVRsolo, or NETGEAR ReadyNAS Surveillance, and confirm your exact software/device version is within the affected ranges (NUUO NVRmini 2 1.7.5–3.0.0, NUUO NVRsolo 1.0.0–3.0.0, ReadyNAS Surveillance 1.1.1–1.4.1).
- Verify the device is reachable from outside your local network (for example, whether port-forwarding or a public IP/remote access exposes it to the internet).
- Since no vendor patch version is listed for this CVE, immediately reduce exposure: restrict access to the device to your internal network only, and remove any unnecessary internet-facing access paths (e.g., remove port forwards / disable remote admin features that publish the endpoint).
- If you cannot fully restrict external access, plan an upgrade or replacement using the vendor’s currently supported firmware for your exact product line, and document the change.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2016-5677 and every CVE in our database. Create a free account — no credit card required.
Create Free Account