EXPOSURES › CVE-2018-14933
CVE-2018-14933
HIGH ⌖ ON CISA KEV · EXPLOITEDNUUO NVRmini devices allow remote OS command execution via shell metacharacters in the uploaddir parameter.
This OS command injection vulnerability enables remote code execution through the uploaddir parameter, posing a severe risk to DIB organizations deploying surveillance hardware. The vulnerability is actively exploited in the KEV list, indicating widespread real-world impact and immediate remediation is required to prevent unauthorized system access.
Shame score — Active exploitation in KEV indicates negligent security posture and avoidable remote code execution risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.