← volver
CVE-2025-1338mediumexplotación observadaCWE-74CWE-77

NUUO Camera handle_config.php print_file command injection

82Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actcvss 6.9epss 51%
de la publicación al arma230 días
Publicada en NVD16 feb
1ª PoC+230d
VulnCheck+417d
probabilidad de explotación
51%top 1% de las CVE
explotación observada
VulnCheck
1 exploit(s) público(s)
A vulnerability was found in NUUO Camera up to 20250203. It has been declared as critical. This vulnerability affects the function print_file of the file /handle_config.php. The manipulation of the argument log leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Productos afectados
NUUO · Camera
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.