CVE-2016-1525 | Netgear Management System NMS300 up to 1.5.0.11 data/config/image.do realName path traversal (ID 135618 / VU#777024)
A vulnerability classified as critical has been found in Netgear Management System NMS300 up to 1.5.0.11. This affects an unknown part of the file data/config/image.do. The manipulation of the argument realName with the input .. leads to path traversal.
This vulnerability is uniquely identified as CVE-2016-1525. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.