Nuuo
45 known vulnerabilities
Top Products
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi
NUUO v03.11.00 was discovered to contain access control issue.
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can ste
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite co
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be res
NUUO CMS all versions 3.1 and prior, The application creates default accounts that have hard-coded passwords, which coul
NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard ac
NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, w
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers
NUUO's NVRMini2 3.8.0 and below contains a backdoor that would allow an unauthenticated remote attacker to take over use
cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP request
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and local
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance
cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticat
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows re
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillanc
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 th
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR Rea
Frequently Asked Questions
How many CVEs affect Nuuo?
Nuuo has 45 CVE records in our database, including 26 critical and 15 high severity vulnerabilities. 2 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Nuuo vulnerabilities?
Nuuo has 26 critical severity (CVSS 9.0+) and 15 high severity (CVSS 7.0-8.9) vulnerabilities. 2 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Nuuo vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Nuuo products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Nuuo Vulnerabilities
CyberStrike scans your infrastructure for Nuuo vulnerabilities and provides real-time remediation guidance.
Get Started