← Back

Nuuo

nuuo

26 CVEs • 18 products

Products (18)

Click to collapse
Toggle
Nvrmini 2
nvrmini_2
Nuuo Cms
nuuo_cms
Nvrsolo
nvrsolo
Crystal
crystal
Nt 4040 Titan
nt-4040_titan
Nvrmini
nvrmini
Nvrmini2
nvrmini2
Ne 2020
ne-2020
Ne 2040
ne-2040
Ne 4080
ne-4080
Ne 4160
ne-4160

CVEs (26)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nuuo
1Nvrsolo Firmware
Jun 17, 2026
Jun 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.
1Nuuo
1Network Video Recorder Firmware
Jul 9, 2026
Mar 29, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
NUUO v03.11.00 was discovered to contain access control issue.
1Nuuo
1Nvrmini2 Firmware
Jun 17, 2026
Jan 14, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined wit...Show more
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.Show less
1Nuuo
1Nvrsolo Firmware
Jun 17, 2026
Dec 28, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can steal the user's session by injecting malicious JavaScript codes which leads to session hijacking.
1Nuuo
1Network Video Recorder Firmware
Jun 17, 2026
May 31, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.
1Nuuo
1Nvrmini2 Firmware
Nov 21, 2024
Dec 5, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the d...Show more
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device.Show less
1Nuuo
1Nvrmini2 Firmware
Nov 21, 2024
Nov 30, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to execute OS commands as root.
1Nuuo
1Nuuo Cms
Nov 21, 2024
Nov 27, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.
1Nuuo
1Nuuo Cms
Nov 21, 2024
Nov 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution.
1Nuuo
1Nuuo Cms
Nov 21, 2024
Nov 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user,...Show more
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an attacker to impersonate a legitimate user, obtain restricted information, or execute arbitrary code.Show less
1Nuuo
1Nuuo Cms
Nov 21, 2024
Oct 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NUUO CMS all versions 3.1 and prior, The application creates default accounts that have hard-coded passwords, which could allow an attacker to gain privileged access.
1Nuuo
1Nuuo Cms
Nov 21, 2024
Oct 12, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard account security features to not be utilized as intended, which could allow user account compromise an...Show more
NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard account security features to not be utilized as intended, which could allow user account compromise and may allow for remote code execution.Show less
1Nuuo
1Nuuo Cms
Nov 21, 2024
Oct 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, which could allow arbitrary code execution.
1Nuuo
1Nuuo Cms
Nov 21, 2024
Oct 12, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.
1Nuuo
1Nvrmini2 Firmware
Nov 21, 2024
Sep 19, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
NUUO's NVRMini2 3.8.0 and below contains a backdoor that would allow an unauthenticated remote attacker to take over user accounts if the file /tmp/moses exists.
1Nuuo
1Nvrmini2 Firmware
Nov 21, 2024
Sep 19, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP requests.
1Nuuo
1Nvrmini Firmware
Nov 7, 2025
Aug 4, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
1Nuuo
1Nt 4040 Titan Firmware
Nov 21, 2024
Jul 13, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and localdisplay:111111. A remote network attacker can gain privileged access to a vulnerable device.
1Nuuo
1Nvrmini 2 Firmware
Nov 21, 2024
May 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
2Netgear
Nuuo
2Nvrmini 2
Readynas Surveillance
May 6, 2026
Aug 31, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary code via the sn parameter to the transf...Show more
Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary code via the sn parameter to the transfer_license command.Show less