CVE-2019-9653

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
31/05/2019
Last modified:
24/08/2020

Description

NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nuuo:network_video_recorder_firmware:*:*:*:*:*:*:*:* 1.7.0 (including) 3.3.0 (including)
cpe:2.3:h:nuuo:network_video_recorder:-:*:*:*:*:*:*:*