CVE-2018-15716: OS Command Injection
Published Nov 30, 2018
·Updated
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgradehandle.php to execute OS commands as root.
Affected Software
5 affected components
NUUO Nvrmini2 Firmware=3.9.1
NUUO Ne-2020
NUUO Ne-2040
NUUO Ne-4080
NUUO Ne-4160
Event History
Nov 30, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-15716?
CVE-2018-15716 is classified as a high severity vulnerability due to its potential for authenticated remote command injection.
2
How do I fix CVE-2018-15716?
To mitigate CVE-2018-15716, upgrade the NUUO NVRMini2 firmware to the latest version where the vulnerability is addressed.
3
What systems are affected by CVE-2018-15716?
CVE-2018-15716 affects NUUO NVRMini2 firmware version 3.9.1 specifically.
4
Can CVE-2018-15716 be exploited remotely?
Yes, CVE-2018-15716 can be exploited remotely by attackers who can authenticate to the system.
5
What kind of attack does CVE-2018-15716 enable?
CVE-2018-15716 enables attackers to execute arbitrary OS commands as root through crafted requests.