CVE-2018-14933 · netVigilance record NV24-0180
NUUO NVRmini Devices OS Command Injection
past due
What to do
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
CISA deadline 2025-01-08 · passed 1 year 8 months ago · applies to US federal civilian agencies; used elsewhere as a reference SLA
What happened
NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
Who is affected
NUUO NVRmini Devices. Affected version ranges are listed in the vendor advisory and the NVD entry linked under Sources.
Weakness class: CWE-78.
Timeline
- Added to CISA KEVExploitation in the wild confirmed by CISA
- CISA remediation deadlinepassed 1 year 8 months ago
Sources
- NVD entry for CVE-2018-14933 nvd.nist.gov/vuln/detail/CVE-2018-14933
- CISA Known Exploited Vulnerabilities catalog www.cisa.gov/known-exploited-vulnerabilities-catalog
- nuuo.com nuuo.com/wp-content/uploads/2023/03/NUUO-EOL-letter%EF%BC%BFNVRmini-2-and-NVRsolo-series.pdf
- nvd.nist.gov nvd.nist.gov/vuln/detail/CVE-2018-14933