rootpwn

high · CVSS v3 8.8

CVE-2026-88622

NUUO Network Video Recorder 2.0.0 is vulnerable to command injection via handle_import_privilege.php, allowing attackers to execute arbitrar

Overview

NUUO Network Video Recorder 2.0.0 is vulnerable to command injection via handle_import_privilege.php, allowing attackers to execute arbitrary commands on the device. This flaw could lead to full compromise of the recorder and any connected network. The vulnerability is exploitable remotely without authentication.

Description

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

Impact

The vulnerability threatens confidentiality, integrity, and availability of the NVR system. Attackers could gain unauthorized access, modify or delete recordings, and disrupt surveillance services. Network administrators and security teams are directly impacted.

Remediation

Apply the vendor’s firmware patch that removes or secures handle_import_privilege.php. If a patch is unavailable, disable the import privilege endpoint or restrict it to trusted IPs. Enforce least privilege on the web interface and segment the NVR from the rest of the network.

Risk context

Severity is high with a CVSS v3 score of 8.8. The flaw is critical for devices running the affected firmware and requires prompt attention.

Affected products

  • NUUO NVR 2.0.0
  • NUUO Network Video Recorder 2.0.0

Scores

Severity
high
CVSS v2
7.5
CVSS v3
8.8
CVSS v4
EPSS

command-injection network-video-recorder NUUO high-severity firmware remote-execution

← All CVEs