Show filters
29 Total Results
Displaying 1-10 of 29
Sort by:
Attacker Value
Moderate
Nuuo Central Management Server Session Bruteforce
Disclosure Date: October 12, 2018 (last updated November 27, 2024)
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.
0
Attacker Value
Unknown
CVE-2025-1338
Disclosure Date: February 16, 2025 (last updated February 16, 2025)
A vulnerability was found in NUUO Camera up to 20250203. It has been declared as critical. This vulnerability affects the function print_file of the file /handle_config.php. The manipulation of the argument log leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2016-15038
Disclosure Date: April 01, 2024 (last updated April 11, 2024)
A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown function of the file /deletefile.php. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258780.
0
Attacker Value
Unknown
CVE-2024-2995
Disclosure Date: March 27, 2024 (last updated April 11, 2024)
A vulnerability was found in NUUO Camera up to 20240319 and classified as problematic. This issue affects some unknown processing of the file /deletefile.php. The manipulation of the argument filename leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258197 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2022-33119
Disclosure Date: June 21, 2022 (last updated February 23, 2025)
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.
0
Attacker Value
Unknown
CVE-2022-25521
Disclosure Date: March 29, 2022 (last updated February 23, 2025)
NUUO v03.11.00 was discovered to contain access control issue.
0
Attacker Value
Unknown
CVE-2022-23227
Disclosure Date: January 14, 2022 (last updated February 23, 2025)
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.
0
Attacker Value
Unknown
CVE-2021-45812
Disclosure Date: December 28, 2021 (last updated February 23, 2025)
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.
0
Attacker Value
Unknown
CVE-2019-9653
Disclosure Date: May 31, 2019 (last updated November 27, 2024)
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.
0
Attacker Value
Unknown
CVE-2018-19864
Disclosure Date: December 05, 2018 (last updated November 27, 2024)
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device.
0