ZeroHour

CVE-2025-1338

large

Remote Command Injection in NUUO Camera Web Interface

CVSS 4.0
6.9 medium
EPSS
51%p99
Published
()
Modified
AI analysis

NUUO Camera devices running builds up to 20250203 contain a critical command injection flaw (CWE-74/CWE-77) in the print_file function of /handle_config.php. The log parameter passed to this endpoint is not properly sanitized, so an unauthenticated remote attacker can submit crafted input that is executed as operating-system commands on the device. Successful exploitation can give the attacker control of the surveillance appliance, access to camera streams and recorded footage, and a foothold to pivot into the network it monitors. Any NUUO Camera deployment with a build dated on or before 2025-02-03 is affected, and the vendor was notified but has not responded. Exploit details have been publicly disclosed, the flaw is not yet in CISA KEV, and there are no confirmed reports of in-the-wild exploitation, though EPSS assigns a high (~51%) probability of exploitation within 30 days.

What to do: Check NUUO's website and support channels for a patched release newer than build 20250203 — the vendor was contacted but did not respond, so a fix may lag. Until a patch is available, restrict internet exposure of the device's web interface (allow only trusted management networks or place it behind a VPN), and use a WAF or reverse proxy to validate or restrict the log parameter on /handle_config.php. Review device and perimeter logs for unexpected command execution or connections to the web interface from unknown sources.

Affected
NUUO Cameraall builds up to and including 20250203 (fixed version not yet known)
Estimated exposure
large≈ tens of thousands of internet-exposed NUUO Camera/NVR systems — NUUO video surveillance appliances are widely deployed in SMB and enterprise CCTV installations, and public internet scans have historically indexed tens of thousands of NUUO devices with web management interfaces exposed for remote…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in NUUO Camera up to 20250203. It has been declared as critical. This vulnerability affects the function print_file of the file /handle_config.php. The manipulation of the argument log leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Weakness
CWE-74, CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news