CVE-2018-14933
CRITICALupgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
Affected Products
nvrmini firmwarenuuoResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
NUUO NVRmini - 'upgrade_handle.php' Remote Command Execution
by Berk Dusunur · Jul 23, 2018
NUUO NVRmini - upgrade_handle.php Remote Command Execution (Metasploit)
by Metasploit · Feb 11, 2019
Frequently Asked Questions
Is CVE-2018-14933 in your stack?
O3 detects CVE-2018-14933 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.