ZeroHour

CVE-2018-14933

KEV PoC ×2large

Unauthenticated OS Command Injection in NUUO NVRmini Enables Remote Code Execution

CISA: NUUO NVRmini Devices OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2018-14933 is an unauthenticated OS command injection flaw (CWE-78) in the upgrade_handle.php script of NUUO NVRmini network video recorder firmware, in which shell metacharacters passed in the 'uploaddir' parameter of a 'writeuploaddir' command are not sanitized. An attacker who sends a crafted HTTP request to this endpoint gains remote command execution on the appliance with no credentials and no user interaction, consistent with the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N. Compromise of the NVR allows an attacker to take over the surveillance appliance, pivot into attached camera networks and connected corporate networks, and stage further attacks such as data theft or ransomware. All organizations running NUUO NVRmini appliances are affected; CISA notes the product is end-of-life/end-of-service, and no version-specific fix range is documented in the available data. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-12-18, two public PoC exploits exist on Exploit-DB, and EPSS assigns a 94.9% probability of exploitation within 30 days.

What to do: Per CISA's required action, discontinue use of the end-of-life/end-of-service NUUO NVRmini product and plan replacement of these appliances; in the interim, remove them from direct internet exposure, restrict management access to trusted networks, and apply any final firmware updates the vendor offers. Check device and firewall logs for unauthenticated HTTP requests to upgrade_handle.php using the writeuploaddir command with shell metacharacters, and treat any hits as potential compromise.

Affected
NUUO NVRmini NVR appliance firmware (nvrmini firmware)
Estimated exposure
large≈10,000–30,000 internet-exposed NUUO NVR devices (tens of thousands) — Order of magnitude estimated from public internet-wide scan data (e.g., Shodan/Censys) that has historically indexed tens of thousands of NUUO NVR web interfaces, consistent with the appliance's broad installed base at SMB and enterprise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

CISA Known Exploited Vulnerability
Affected
NUUO NVRmini Devices
Required action
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Due date
Ransomware use
Unknown
Vendors
nuuo
Products
nvrmini firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.