NUUO Camera handle_config.php print_file command injection
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 6.9epss 51%
from disclosure to weapon230 days
Published on NVDFeb 16
1st PoC+230d
VulnCheck+417d
exploitation probability
51%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
A vulnerability was found in NUUO Camera up to 20250203. It has been declared as critical. This vulnerability affects the function print_file of the file /handle_config.php. The manipulation of the argument log leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected products
NUUO · Camerapublic PoCs found — 1
vulncheckvulncheck.com/xdb/44869632fc17unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.