target entity

NUUO

2 source-linked records in the current knowledge graph.

high

CVE-2022-23227: NUUO NVRmini2 Devices Missing Authentication Vulnerability

NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2022-23227EPSS 49.4%NUUONVRmini2 Devices
CISA KEV ↗ · unattributed attribution
high

CVE-2018-14933: NUUO NVRmini Devices OS Command Injection Vulnerability

NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2018-14933EPSS 93.7%NUUONVRmini Devices
CISA KEV ↗ · unattributed attribution