Nuuo develops a focused line of network video recorders and surveillance management software deployed in security and monitoring infrastructure, where its relatively small product portfolio has attracted a disproportionate volume of security disclosures. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the exposed nature of internet-connected surveillance systems and the high value of command-execution flaws in embedded firmware and management interfaces. The exposure recurs across products such as NVRmini2, NVRSolo, and Nuuo CMS through a durable set of weakness classes—OS command injection, improper input validation, buffer overflows, hard-coded credentials, and cross-site scripting—that are characteristic of older embedded software architectures with minimal input sanitization and authentication hardening. Defenders should treat Nuuo surveillance appliances as high-risk if internet-reachable and prioritize patching or segmentation; live exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nuuo over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14933CRITICAL upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command. | Aug 4, 2018 | 9.8 | 99 | YES | YES |
CVE-2016-5674CRITICAL __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attacke | Aug 31, 2016 | 9.8 | 93 | NO | YES |
CVE-2022-23227CRITICAL NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_us | Jan 14, 2022 | 9.8 | 88 | YES | NO |
CVE-2016-5675CRITICAL handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through | Aug 31, 2016 | 9.8 | 85 | NO | YES |
CVE-2018-18982HIGH NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow a | Nov 27, 2018 | 8.8 | 78 | NO | YES |
CVE-2016-5676HIGH cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the a | Aug 31, 2016 | 7.5 | 68 | NO | YES |
CVE-2018-17888CRITICAL NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary | Oct 12, 2018 | 9.8 | 59 | NO | YES |
CVE-2018-19864CRITICAL NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability t | Dec 5, 2018 | 9.8 | 54 | NO | YES |
CVE-2018-17934CRITICAL NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an at | Nov 27, 2018 | 9.8 | 51 | NO | YES |
CVE-2018-17936CRITICAL NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote co | Nov 27, 2018 | 9.8 | 49 | NO | YES |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nuuo.
Media articles that mention a CVE ID that affects a product developed by Nuuo — matched by CVE ID, not by vendor name.