vendor:
NUUO NVRmini, NVRmini2, Crystal and NVRSolo
by:
Gjoko 'LiquidWorm' Krstic
9,8
CVSS
HIGH
Command Injection
78
CWE
Product Name: NUUO NVRmini, NVRmini2, Crystal and NVRSolo
Affected Version From: <=3.0.8
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: GNU/Linux 3.0.8 (armv7l), GNU/Linux 2.6.31.8 (armv5tel), lighttpd/1.4.28, PHP/5.5.3
2016
NUUO Remote Root Exploit
NUUO NVRmini, NVRmini2, Crystal and NVRSolo suffers from an unauthenticated command injection vulnerability. Due to an undocumented and hidden debugging script, an attacker can inject and execute arbitrary code as the root user via the 'log' GET parameter in the '__debugging_center_utils___.php' script.
Mitigation:
Upgrade to the latest version of NUUO NVRmini, NVRmini2, Crystal and NVRSolo.