CVE-2018-14933
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- NUUO NVRmini Devices OS Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
תיאור (מקור, אנגלית)
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 94% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-78
מוצרים מושפעים
nuuo: nvrmini firmware; nuuo: nvrmini
קישורים
- https://www.exploit-db.com/exploits/45070/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46340/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/45070/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46340/ ExploitThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource