Skip to content
COOEY

FAIL › dossier

nuuo

VENDOR

· dossier confidence 20%

NUUO is a surveillance hardware vendor with a documented history of critical and high-severity vulnerabilities in its NVR devices, including remote code execution and unauthorized access vectors. Its security posture is weak, requiring immediate remediation and enhanced monitoring for defense-industrial-base partners.

PROFILE
CategoryvendorWhat they doNUUO develops and sells network video recorder (NVR) and surveillance hardware and software solutions. Websitehttps://www.nuuo.com ↗
SECURITY POSTURE

NUUO has a poor security track record with multiple high and critical vulnerabilities in its NVRmini and NVRmini2 devices, including remote code execution and unauthorized user creation.

Notable failures
  • CVE-2018-14933 RCE in NVRmini
  • CVE-2022-23227 unauthenticated user creation in NVRmini2
  • CVE-2022-25521 access control issue in v03.11.00
Patterns: unpatched edge-device RCEs; weak access controls in surveillance firmware
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2024-12-18 CVE-2018-14933 high NUUO NVRmini devices allow remote OS command execution via shell metacharacters in the uploaddir parameter.
2024-12-18 CVE-2022-23227 high NUUO NVRmini2 devices allow unauthenticated attackers to add arbitrary users via encrypted TAR archives, enabling unauthorized access to surveillance systems.
2022-03-29 CVE-2022-25521 critical NUUO v03.11.00 was discovered to contain access control issue.
Open questions: Exact founding year and HQ location not explicitly confirmed in provided web evidence · Current size and ownership structure not documented in supplied sources
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-26 04:28:43.990882+00:00