Description
NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to the /tmp/ directory, with the filename derived from basename() of the URL. This operation requires no authentication.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The vulnerability is an unauthenticated arbitrary file read flaw located in the up.php page of NUUO Network Video Recorder version 2.0.0. The application accepts a "url" parameter in a POST request, then uses fopen to open that URL and writes the content into /tmp with a filename derived from the URL's basename. Because no authentication or input validation is performed, an attacker can supply any file path or remote URL that PHP is able to open, enabling read access to local files such as configuration files, credentials, or logs. This directly violates the confidentiality of the system and allows disclosure of sensitive data.

Affected Systems

The affected product is NUUO Network Video Recorder 2.0.0. No vendor or product vendor strings are listed, and the vulnerable code is part of the proprietary firmware or web interface shipped by NUUO. The flaw has been demonstrated in the released 2.0.0 build, and any installations that have not applied a post‑release patch are susceptible.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of <1% shows a low likelihood of exploitation at this time, and it is not listed in CISA KEV. Because the flaw requires no authentication and has no input similarity checks, the vulnerability is trivially exploitable when allow_url_fopen is enabled. Based on the description, it is inferred that this condition must be present for exploitation. The lack of authentication and the ability to read arbitrary files indicate a high impact condition, and the business impact of exposing configuration or credential files warrants urgent remediation.

Generated by OpenCVE AI on September 22, 2026 at 22:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest NUUO Network Video Recorder release that addresses the read‑through vulnerability.
  • Disable PHP's allow_url_fopen setting or remove it from the configuration if remote file access is not required.
  • Add input validation on the 'url' parameter to restrict uploads to a safe whitelist of domains or to static file paths and enforce strict file path checks before using basename or writing to disk.
  • Require authentication before allowing the up.php endpoint to be called so that only authorized users can trigger the file read operation.

Generated by OpenCVE AI on September 22, 2026 at 22:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Arbitrary File Read in NUUO Network Video Recorder 2.0.0

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-552
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Arbitrary File Read in NUUO Network Video Recorder 2.0.0

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Nuuo
Nuuo network Video Recorder
Vendors & Products Nuuo
Nuuo network Video Recorder

Sat, 19 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Arbitrary File Read in NUUO Network Video Recorder
Weaknesses CWE-200

Sat, 19 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Arbitrary File Read in NUUO Network Video Recorder
Weaknesses CWE-200

Fri, 18 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to the /tmp/ directory, with the filename derived from basename() of the URL. This operation requires no authentication.
References

Subscriptions

Nuuo Network Video Recorder
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T18:27:49.804Z

Reserved: 2026-09-10T00:00:00.000Z

Link: CVE-2026-88623

cve-icon Vulnrichment

Updated: 2026-09-22T18:10:21.727Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T14:19:02.617

Modified: 2026-09-22T19:43:52.337

Link: CVE-2026-88623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T22:15:07Z

Weaknesses
  • CWE-552

    Files or Directories Accessible to External Parties