CVE-2018-14933
CVE-2018-14933
In short
A NUUO NVRmini device has a critical flaw in its upgrade tool that lets attackers execute arbitrary commands by inserting shell commands into the upload directory parameter. This allows complete control over the device without authentication.
Technical detail
Remote Command Injection in upgrade_handle.php via improper sanitization of the uploaddir parameter in writeuploaddir commands. Attackers can inject shell metacharacters to execute arbitrary system commands with device privileges, requiring only network access to the affected endpoint.
Summary generated and translated by AI from the official description.
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 3
cve_referencewww.exploit-db.com/exploits/46340/unverifiedexploitdbwww.exploit-db.com/exploits/46340unverifiedcve_referencewww.exploit-db.com/exploits/45070/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →