Executive brief
NUUO NVRmini2 devices contain a missing authentication vulnerability in handle_import_user.php. An unauthenticated attacker can upload an encrypted TAR archive to add arbitrary users, which can be combined with other flaws to achieve root-level remote code execution.
Affected products
- NUUO NVRmini2 firmware up to and including 3.11.0
- NUUO NVRmini2
Timeline
- 2022-01-21: disclosed: Initial analysis by NIST
- 2024-12-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog