Описание
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- US Government Resource
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:nuuo:nvrmini_firmware:2016:*:*:*:*:*:*:*
cpe:2.3:h:nuuo:nvrmini:-:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.93755
Критический
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-78
CWE-78
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
EPSS
Процентиль: 100%
0.93755
Критический
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-78
CWE-78