Description
NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.
Published: 2026-09-18
Score: 8.8 High
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a command injection flaw (CWE‑77) located in the handle_import_privilege.php script of NUUO Network Video Recorder version 2.0.0. An attacker who can influence the import privilege process can supply crafted input that is executed by the underlying operating system, enabling arbitrary command execution on the host. This gives the attacker full compromise of confidentiality, integrity, and availability of the device.

Affected Systems

This flaw affects NUUO Network Video Recorder software, specifically version 2.0.0. The vulnerability resides in a publicly exposed web interface that handles privilege imports. No additional vendor or product attribution is listed, but the device is a network video recorder running NUUO firmware.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score of 1% shows a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers likely target the exposed HTTP/HTTPS endpoint that triggers the handle_import_privilege.php script, sending specially crafted requests to inject shell commands. Successful exploitation would allow the attacker to execute arbitrary system commands, potentially taking full control of the recorder.

Generated by OpenCVE AI on September 20, 2026 at 00:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any official patch or update from NUUO when it becomes available.
  • Restrict network access to the recorder’s web interface to trusted hosts only.
  • Disable or remove the handle_import_privilege.php functionality if it is not required for business operations.
  • Monitor web and system logs for suspicious command execution activity.

Generated by OpenCVE AI on September 20, 2026 at 00:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Command Injection in NUUO Network Video Recorder handle_import_privilege.php

Sat, 19 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Command Injection in NUUO Network Video Recorder Import Privilege Handler

Sat, 19 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Nuuo
Nuuo network Video Recorder
Vendors & Products Nuuo
Nuuo network Video Recorder

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Command Injection in NUUO Network Video Recorder Import Privilege Handler

Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Fri, 18 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.
References

Subscriptions

Nuuo Network Video Recorder
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-18T14:23:46.959Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88622

cve-icon Vulnrichment

Updated: 2026-09-18T14:23:35.874Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:02.480

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-88622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:15:06Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')