CVE-2022-23227
KEV PoC ×3nicheMissing Authentication in NUUO NVRmini2 Devices Lets Attackers Add Arbitrary Users
CISA: NUUO NVRmini2 Devices Missing Authentication Vulnerability
NUUO NVRmini2 network video recorders fail to require authentication for a remote archive-upload function, so an unauthenticated attacker can upload a specially crafted encrypted TAR archive to the device. By abusing this mechanism, the attacker can add arbitrary user accounts, gaining authenticated access to the NVR's management and surveillance features. Any organization still running a NUUO NVRmini2 appliance is affected; the product line is end-of-life/end-of-service and no longer receiving fixes. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-18, indicating exploitation in the wild, though ransomware use has not been confirmed. EPSS assigns a roughly 48.5% probability of exploitation within 30 days (99th percentile), and CISA's required action is to discontinue use of the product.
What to do: Because the product is end-of-life/end-of-service and no patch is available, retire or replace NVRmini2 appliances as CISA's KEV required action directs. If replacement is not immediate, remove the device's web interface from direct internet exposure (restrict via firewall/ACL or VPN) and audit device accounts and logs for unexpectedly added users.
| NUUO NVRmini2 devices | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.
- Affected
- NUUO NVRmini2 Devices
- Required action
- The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
- Due date
- Ransomware use
- Unknown
- Vendors
- nuuo
- Products
- nvrmini2 firmware
- Weakness
- CWE-306
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.