CVE-2018-14933
CVE-2018-14933
Vexday Risk Score
100Fix now
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 9.8EPSS 93.7%KEV simPoC públicaPatch —
Lifecycle
04 Aug 2018Published on NVD
11 Feb 2019Public PoC
18 Dec 2024Active exploitation (CISA KEV)
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short
A NUUO NVRmini device has a critical flaw in its upgrade tool that lets attackers execute arbitrary commands by inserting shell commands into the upload directory parameter. This allows complete control over the device without authentication.
Technical detail
Remote Command Injection in upgrade_handle.php via improper sanitization of the uploaddir parameter in writeuploaddir commands. Attackers can inject shell metacharacters to execute arbitrary system commands with device privileges, requiring only network access to the affected endpoint.
Summary generated and translated by AI from the official description.
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 3
cve_referencewww.exploit-db.com/exploits/46340/unverifiedexploitdbwww.exploit-db.com/exploits/46340unverifiedcve_referencewww.exploit-db.com/exploits/45070/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →