CVE-2025-1338: NUUO Camera handle_config.php print_file command injection
A vulnerability was found in NUUO Camera up to 20250203. It has been declared as critical. This vulnerability affects the function printfile of the file /handleconfig.php. The manipulation of the argument log leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1338?
CVE-2025-1338 has been declared as critical due to the potential for remote command injection.
How do I fix CVE-2025-1338?
To fix CVE-2025-1338, update NUUO Camera to a version later than 20250203.
What is the impact of CVE-2025-1338?
CVE-2025-1338 allows an attacker to manipulate log arguments leading to command injection vulnerabilities.
Who is affected by CVE-2025-1338?
CVE-2025-1338 affects users of NUUO Camera up to and including version 20250203.
Is CVE-2025-1338 exploitable remotely?
Yes, CVE-2025-1338 can be exploited remotely, allowing attackers to execute commands on the affected system.