← back
CVE-2018-14933

CVE-2018-14933

CVSS 9.8 CRITICALEPSS 93.7%● KEVCWE-78
In short

A NUUO NVRmini device has a critical flaw in its upgrade tool that lets attackers execute arbitrary commands by inserting shell commands into the upload directory parameter. This allows complete control over the device without authentication.

Technical detail

Remote Command Injection in upgrade_handle.php via improper sanitization of the uploaddir parameter in writeuploaddir commands. Attackers can inject shell metacharacters to execute arbitrary system commands with device privileges, requiring only network access to the affected endpoint.

Summary generated and translated by AI from the official description.
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →