ZeroHour

CVE-2022-23227

KEV PoC ×3niche

Missing Authentication in NUUO NVRmini2 Devices Lets Attackers Add Arbitrary Users

CISA: NUUO NVRmini2 Devices Missing Authentication Vulnerability

CVSS 3.1
9.8 critical
EPSS
48%p99
Published
()
KEV added
AI analysis

NUUO NVRmini2 network video recorders fail to require authentication for a remote archive-upload function, so an unauthenticated attacker can upload a specially crafted encrypted TAR archive to the device. By abusing this mechanism, the attacker can add arbitrary user accounts, gaining authenticated access to the NVR's management and surveillance features. Any organization still running a NUUO NVRmini2 appliance is affected; the product line is end-of-life/end-of-service and no longer receiving fixes. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-18, indicating exploitation in the wild, though ransomware use has not been confirmed. EPSS assigns a roughly 48.5% probability of exploitation within 30 days (99th percentile), and CISA's required action is to discontinue use of the product.

What to do: Because the product is end-of-life/end-of-service and no patch is available, retire or replace NVRmini2 appliances as CISA's KEV required action directs. If replacement is not immediate, remove the device's web interface from direct internet exposure (restrict via firewall/ACL or VPN) and audit device accounts and logs for unexpectedly added users.

Affected
NUUO NVRmini2 devices
Estimated exposure
nichelikely only a low thousands of deployed NVRmini2 appliances (historical public scans of NUUO devices counted in the low thousands) — NUUO is a niche surveillance vendor whose NVRmini2 line is EoL, and public internet scans of its devices have historically shown exposed units only in the low thousands, placing the deployed base below the 10k-100k tier.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.

CISA Known Exploited Vulnerability
Affected
NUUO NVRmini2 Devices
Required action
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
Due date
Ransomware use
Unknown
Vendors
nuuo
Products
nvrmini2 firmware
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.