A security researcher has released the exploit code for two serious vulnerabilities in Netgear ProSAFE NMS300 network management system. Remote code execution vulnerability received a CVSS score of 8.3, it can be exploited by sending a specially crafted POST request to one of two Java servlets. The second flaw (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) is a directory traversal that could be exploited. The flaws were reported to Netgear via CERT/CC in December, but the issues are still in the systems.”]
Source: http://securityaffairs.co/wordpress/44237/hacking/netgear-prosafe-nms300-flaws.html