vendor:
NVRmini
by:
Berk Dusunur, numan turle
9.8
CVSS
CRITICAL
Remote Command Execution
CWE
Product Name: NVRmini
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2018-14933
CPE:
Platforms Tested: Unix, Windows, Linux
2018
NUUO NVRmini upgrade_handle.php Remote Command Execution
This exploits a vulnerability in the web application of NUUO NVRmini IP camera, which can be done by triggering the writeuploaddir command in the upgrade_handle.php file.
Mitigation:
Apply the latest security patches provided by the vendor.