Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2018-14933

NUUO NVRmini Devices OS Command Injection Vulnerability

NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

cat cve-2018-14933.json
Vendor
NUUO
Product
NVRmini Devices
CVSS
9.8
EPSS (exploit probability)
94.9%
Status
kev
CISA patch-by (BOD 22-01)
Published

NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

Added to CISA’s Known Exploited Vulnerabilities catalog on 2024-12-18. Required action per CISA: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Due date: 2025-01-08.

This is an auto-synced KEV catalog record pending a full 0dayNews write-up — see CISA’s KEV catalog and the NVD record linked above for primary sources.