VulnerabilityModified
CVE-2019-9653
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.
CRITICAL 9.8EPSS 11.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 11.49% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- nuuo/network video recorder firmware
- Source
- cve@mitre.org
References
- https://github.com/grayoneday/CVE-2019-9653Exploit, Third Party Advisory
- https://www.nccst.nat.gov.tw/NewsRSS?lang=en&RSSType=mssecurityThird Party Advisory
- https://www.nuuo.com/DownloadMainpage.phpProduct, Vendor Advisory
- https://github.com/grayoneday/CVE-2019-9653Exploit, Third Party Advisory
- https://www.nccst.nat.gov.tw/NewsRSS?lang=en&RSSType=mssecurityThird Party Advisory
- https://www.nuuo.com/DownloadMainpage.phpProduct, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.