vendor:
NUUO NVR
by:
Berk Dusunur
7.5
CVSS
HIGH
Unauthenticated Remote Code Execution
CWE
Product Name: NUUO NVR
Affected Version From: v2016
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Parrot OS
2018
NUUO NVR Unauthenticated Remote Code Execution
The NUUO NVR software allows unauthenticated remote attackers to execute arbitrary code via a crafted HTTP request to the upgrade_handle.php script. By manipulating the 'uploaddir' parameter, an attacker can execute arbitrary commands on the target system.
Mitigation:
Upgrade to the latest version of the NUUO NVR software.