high · CVSS v3 8.8
CVE-2026-88622
NUUO Network Video Recorder 2.0.0 is vulnerable to command injection via handle_import_privilege.php, allowing attackers to execute arbitrar
Overview
NUUO Network Video Recorder 2.0.0 is vulnerable to command injection via handle_import_privilege.php, allowing attackers to execute arbitrary commands on the device. This flaw could lead to full compromise of the recorder and any connected network. The vulnerability is exploitable remotely without authentication.
Description
NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.
Impact
The vulnerability threatens confidentiality, integrity, and availability of the NVR system. Attackers could gain unauthorized access, modify or delete recordings, and disrupt surveillance services. Network administrators and security teams are directly impacted.
Remediation
Apply the vendor’s firmware patch that removes or secures handle_import_privilege.php. If a patch is unavailable, disable the import privilege endpoint or restrict it to trusted IPs. Enforce least privilege on the web interface and segment the NVR from the rest of the network.
Risk context
Severity is high with a CVSS v3 score of 8.8. The flaw is critical for devices running the affected firmware and requires prompt attention.
Affected products
- NUUO NVR 2.0.0
- NUUO Network Video Recorder 2.0.0
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 8.8
- CVSS v4
- —
- EPSS
- —