ZeroHour

Vulnerabilities

26 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-33119
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.

NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.

NVD description · AI analysis pending
6.12% PoC
  • nuuo nvrsolo firmware
CVE-2022-25521
NUUO v03.11.00 was discovered to contain access control issue.

NUUO v03.11.00 was discovered to contain access control issue.

NVD description · AI analysis pending
9.82%
  • nuuo network video recorder firmware
CVE-2022-23227
Missing Authentication in NUUO NVRmini2 Devices Lets Attackers Add Arbitrary Users

NUUO NVRmini2 network video recorders fail to require authentication for a remote archive-upload function, so an unauthenticated attacker can upload a specially crafted encrypted TAR archive to the device. By abusing this mechanism, the attacker can add arbitrary user accounts, gaining authenticated access to the NVR's management and surveillance features. Any organization still running a NUUO NVRmini2 appliance is affected; the product line is end-of-life/end-of-service and no longer receiving fixes. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-18, indicating exploitation in the wild, though ransomware use has not been confirmed. EPSS assigns a roughly 48.5% probability of exploitation within 30 days (99th percentile), and CISA's required action is to discontinue use of the product.

Do: Because the product is end-of-life/end-of-service and no patch is available, retire or replace NVRmini2 appliances as CISA's KEV required action directs. If replacement is not immediate, remove the device's web interface from direct internet exposure (restrict via firewall/ACL or VPN) and audit device accounts and logs for unexpectedly added users.

9.848% KEV PoC ×3
  • NUUO NVRmini2 devices
nichelikely only a low thousands of deployed NVRmini2 appliances (historical public scans of NUUO devices counted in the low thousands)
CVE-2021-45812
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability.

NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.

NVD description · AI analysis pending
6.1<1% PoC
  • nuuo nvrsolo firmware
CVE-2019-9653
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_

NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.

NVD description · AI analysis pending
9.811% PoC
  • nuuo network video recorder firmware
CVE-2018-19864
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), re

NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device.

NVD description · AI analysis pending
9.825%
  • nuuo nvrmini2 firmware
CVE-2018-15716
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection.

NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to execute OS commands as root.

NVD description · AI analysis pending
8.818% PoC ×3
  • nuuo nvrmini2 firmware
CVE-2018-17934
+2 in the same advisory: …17936 …18982
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory.

NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code.

NVD description · AI analysis pending
9.8
group max
20%
  • nuuo nuuo cms
CVE-2018-17888
+3 in the same advisory: …17890 …17894 …17892
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which c

NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.

NVD description · AI analysis pending
9.8
group max
30%
  • nuuo nuuo cms
CVE-2018-1149
+1 in the same advisory: …1150
cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP requests.

cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP requests.

NVD description · AI analysis pending
9.8
group max
15% PoC ×2
  • nuuo nvrmini2 firmware
CVE-2018-14933
Unauthenticated OS Command Injection in NUUO NVRmini Enables Remote Code Execution

CVE-2018-14933 is an unauthenticated OS command injection flaw (CWE-78) in the upgrade_handle.php script of NUUO NVRmini network video recorder firmware, in which shell metacharacters passed in the 'uploaddir' parameter of a 'writeuploaddir' command are not sanitized. An attacker who sends a crafted HTTP request to this endpoint gains remote command execution on the appliance with no credentials and no user interaction, consistent with the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N. Compromise of the NVR allows an attacker to take over the surveillance appliance, pivot into attached camera networks and connected corporate networks, and stage further attacks such as data theft or ransomware. All organizations running NUUO NVRmini appliances are affected; CISA notes the product is end-of-life/end-of-service, and no version-specific fix range is documented in the available data. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-12-18, two public PoC exploits exist on Exploit-DB, and EPSS assigns a 94.9% probability of exploitation within 30 days.

Do: Per CISA's required action, discontinue use of the end-of-life/end-of-service NUUO NVRmini product and plan replacement of these appliances; in the interim, remove them from direct internet exposure, restrict management access to trusted networks, and apply any final firmware updates the vendor offers. Check device and firewall logs for unauthenticated HTTP requests to upgrade_handle.php using the writeuploaddir command with shell metacharacters, and treat any hits as potential compromise.

9.895% KEV PoC ×2
  • NUUO NVRmini NVR appliance firmware (nvrmini firmware)
large≈10,000–30,000 internet-exposed NUUO NVR devices (tens of thousands)
CVE-2016-6553
Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of:

Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and localdisplay:111111. A remote network attacker can gain privileged access to a vulnerable device.

NVD description · AI analysis pending
9.83%
  • nuuo nt-4040 titan firmware
CVE-2018-11523
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.

upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.

NVD description · AI analysis pending
9.810% PoC
  • nuuo nvrmini 2 firmware
CVE-2016-5678
+2 in the same advisory: …5680 …5679
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative

NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.

NVD description · AI analysis pending
9.8
group max
9%
  • nuuo nvrmini 2
  • nuuo nvrsolo
CVE-2016-5674
+3 in the same advisory: …5675 …5676 …5677
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 a

__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.

NVD description · AI analysis pending
9.8
group max
95%
  • netgear readynas surveillance
  • netgear nvrmini 2
  • netgear nvrsolo