First published: Thu Nov 29 2018(Updated: )
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to execute OS commands as root.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nuuo Nvrmini2 Firmware | =3.9.1 | |
Nuuo Ne-2020 | ||
Nuuo Ne-2040 | ||
Nuuo Ne-4080 | ||
Nuuo Ne-4160 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-15716 is classified as a high severity vulnerability due to its potential for authenticated remote command injection.
To mitigate CVE-2018-15716, upgrade the NUUO NVRMini2 firmware to the latest version where the vulnerability is addressed.
CVE-2018-15716 affects NUUO NVRMini2 firmware version 3.9.1 specifically.
Yes, CVE-2018-15716 can be exploited remotely by attackers who can authenticate to the system.
CVE-2018-15716 enables attackers to execute arbitrary OS commands as root through crafted requests.