Skip to main content

CVE-2016-1525

8.6
HIGHCVSS v3.1 Base Score
80.31%
HIGH RiskEPSS (99th percentile)

Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a .. (dot dot) in the realName parameter.

Published: 2/13/2016
Modified: 4/12/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.6HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

EPSS Score (Exploitation Probability)

80.31%HIGH Exploitation Risk
99th percentile

This vulnerability has a 80.31% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

Related Vulnerabilities