First published: Sun Feb 16 2025(Updated: )
A vulnerability was found in NUUO Camera up to 20250203. It has been declared as critical. This vulnerability affects the function print_file of the file /handle_config.php. The manipulation of the argument log leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
NUUO Camera | <20250203 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1338 has been declared as critical due to the potential for remote command injection.
To fix CVE-2025-1338, update NUUO Camera to a version later than 20250203.
CVE-2025-1338 allows an attacker to manipulate log arguments leading to command injection vulnerabilities.
CVE-2025-1338 affects users of NUUO Camera up to and including version 20250203.
Yes, CVE-2025-1338 can be exploited remotely, allowing attackers to execute commands on the affected system.