Impact
The vulnerability is a command injection flaw (CWE‑77) located in the handle_import_privilege.php script of NUUO Network Video Recorder version 2.0.0. An attacker who can influence the import privilege process can supply crafted input that is executed by the underlying operating system, enabling arbitrary command execution on the host. This gives the attacker full compromise of confidentiality, integrity, and availability of the device.
Affected Systems
This flaw affects NUUO Network Video Recorder software, specifically version 2.0.0. The vulnerability resides in a publicly exposed web interface that handles privilege imports. No additional vendor or product attribution is listed, but the device is a network video recorder running NUUO firmware.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of 1% shows a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers likely target the exposed HTTP/HTTPS endpoint that triggers the handle_import_privilege.php script, sending specially crafted requests to inject shell commands. Successful exploitation would allow the attacker to execute arbitrary system commands, potentially taking full control of the recorder.
OpenCVE Enrichment