CVE-2018-1150 describes a backdoor in NUUO NVRMini2 firmware versions 3.8.0 and below, allowing unauthenticated remote attackers to compromise user accounts if a specific file (/tmp/moses) exists. This vulnerability carries a CVSSv3 score of 7.3 (HIGH), indicating a low-complexity attack that can lead to partial loss of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, the vulnerability has garnered significant community attention with two media articles and two community mentions. Despite its age, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.8.0CPE matchmatch criteria | cpe:2.3:o:nuuo:nvrmini2_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R2] Multiple NUUO NVRMini2 Vulnerabilities
Sep 17, 2018[R2] Multiple NUUO NVRMini2 Vulnerabilities
Sep 17, 2018Multiple NUUO NVRMini2 Vulnerabilities
Sep 17, 2018[R2] Multiple NUUO NVRMini2 Vulnerabilities
Sep 17, 2018