Network Video Recorder NVRsolo
by Nuuo
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-19864 | Cri | 0.69 | 9.8 | 0.25 | Dec 5, 2018 | NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device. | ||
| CVE-2019-9653 | Cri | 0.65 | 9.8 | 0.11 | May 31, 2019 | NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php. | ||
| CVE-2026-88622 | Hig | 0.57 | 8.8 | — | Sep 18, 2026 | NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php. | ||
| CVE-2022-33119 | Med | 0.40 | 6.1 | 0.02 | Jun 21, 2022 | NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php. | ||
| CVE-2021-45812 | Med | 0.40 | 6.1 | 0.01 | Dec 28, 2021 | NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking. | ||
| CVE-2026-88623 | 0.00 | — | — | Sep 18, 2026 | NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to the /tmp/ directory, with the filename… |
- risk 0.69cvss 9.8epss 0.25
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device.
- risk 0.65cvss 9.8epss 0.11
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.
- risk 0.57cvss 8.8epss —
NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.
- risk 0.40cvss 6.1epss 0.02
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.
- risk 0.40cvss 6.1epss 0.01
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.
- CVE-2026-88623Sep 18, 2026risk 0.00cvss —epss —
NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to the /tmp/ directory, with the filename…