Critical severity9.8NVD Advisory· Published Sep 19, 2018· Updated Jun 17, 2026
CVE-2018-1149
CVE-2018-1149
Description
cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- NUUO/NUUO NVRMini2v5Range: All versions prior to version 3.9.1
Patches
Vulnerability mechanics
References
4- github.com/tenable/poc/tree/master/nuuo/nvrmini2nvdExploitThird Party Advisory
- www.tenable.com/security/research/tra-2018-25nvdExploitThird Party Advisory
- www.securityfocus.com/bid/105720nvdThird Party AdvisoryVDB Entry
- www.nuuo.com/backend/CKEdit/upload/files/NUUO_NVRsolo_v3_9_1_Release%20note.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.