NUUO NVRmini Devices OS Command Injection Vulnerability
Vendor: NUUO
Product: NVRmini Devices
Added: 2024-12-18
Due Date: 2025-01-08
Description:
NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
Required Action:
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
CWEs: