Junglewise Threat Intelligence

CVE-2022-23227: NUUO NVRmini2 Devices Missing Authentication Vulnerability

CVE-2022-23227 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-12-18

Executive brief

NUUO NVRmini2 devices contain a missing authentication vulnerability in handle_import_user.php. An unauthenticated attacker can upload an encrypted TAR archive to add arbitrary users, which can be combined with other flaws to achieve root-level remote code execution.

Affected products

  • NUUO NVRmini2 firmware up to and including 3.11.0
  • NUUO NVRmini2

Timeline

  • 2022-01-21: disclosed: Initial analysis by NIST
  • 2024-12-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog