Show filters
29 Total Results
Displaying 1-10 of 29
Sort by:
Attacker Value
Moderate

Nuuo Central Management Server Session Bruteforce

Disclosure Date: October 12, 2018 (last updated November 27, 2024)
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.
0
Attacker Value
Unknown

CVE-2025-1338

Disclosure Date: February 16, 2025 (last updated February 16, 2025)
A vulnerability was found in NUUO Camera up to 20250203. It has been declared as critical. This vulnerability affects the function print_file of the file /handle_config.php. The manipulation of the argument log leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2016-15038

Disclosure Date: April 01, 2024 (last updated April 11, 2024)
A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown function of the file /deletefile.php. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258780.
0
Attacker Value
Unknown

CVE-2024-2995

Disclosure Date: March 27, 2024 (last updated April 11, 2024)
A vulnerability was found in NUUO Camera up to 20240319 and classified as problematic. This issue affects some unknown processing of the file /deletefile.php. The manipulation of the argument filename leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258197 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2022-33119

Disclosure Date: June 21, 2022 (last updated February 23, 2025)
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.
Attacker Value
Unknown

CVE-2022-25521

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
NUUO v03.11.00 was discovered to contain access control issue.
Attacker Value
Unknown

CVE-2022-23227

Disclosure Date: January 14, 2022 (last updated February 23, 2025)
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.
Attacker Value
Unknown

CVE-2021-45812

Disclosure Date: December 28, 2021 (last updated February 23, 2025)
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.
Attacker Value
Unknown

CVE-2019-9653

Disclosure Date: May 31, 2019 (last updated November 27, 2024)
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.
0
Attacker Value
Unknown

CVE-2018-19864

Disclosure Date: December 05, 2018 (last updated November 27, 2024)
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device.
0