Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nuuo

First CVE: Aug 31, 2016Active for: 10 yearsTotal CVEs: 26
78.3
VTI Score
TOP TARGET

Nuuo develops a focused line of network video recorders and surveillance management software deployed in security and monitoring infrastructure, where its relatively small product portfolio has attracted a disproportionate volume of security disclosures. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the exposed nature of internet-connected surveillance systems and the high value of command-execution flaws in embedded firmware and management interfaces. The exposure recurs across products such as NVRmini2, NVRSolo, and Nuuo CMS through a durable set of weakness classes—OS command injection, improper input validation, buffer overflows, hard-coded credentials, and cross-site scripting—that are characteristic of older embedded software architectures with minimal input sanitization and authentication hardening. Defenders should treat Nuuo surveillance appliances as high-risk if internet-reachable and prioritize patching or segmentation; live exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
9.1
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked vendors
7.7%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Nuuo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2016
9 years ago
Most Recent CVE
Jun 21, 2022
1,494 days ago

Products(18 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-14933CRITICAL
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
Aug 4, 20189.899YESYES
CVE-2016-5674CRITICAL
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attacke
Aug 31, 20169.893NOYES
CVE-2022-23227CRITICAL
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_us
Jan 14, 20229.888YESNO
CVE-2016-5675CRITICAL
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through
Aug 31, 20169.885NOYES
CVE-2018-18982HIGH
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow a
Nov 27, 20188.878NOYES
CVE-2016-5676HIGH
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the a
Aug 31, 20167.568NOYES
CVE-2018-17888CRITICAL
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary
Oct 12, 20189.859NOYES
CVE-2018-19864CRITICAL
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability t
Dec 5, 20189.854NOYES
CVE-2018-17934CRITICAL
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the intended directory. This could allow an at
Nov 27, 20189.851NOYES
CVE-2018-17936CRITICAL
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote co
Nov 27, 20189.849NOYES
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
31%
62%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network26 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None24 (92.3%)
Unknown0 (0.0%)
Required2 (7.7%)
Privileges Required
Low5 (19.2%)
High0 (0.0%)
None21 (80.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
2 CVEs
7.7% of CVEs· 100th percentile
Metasploit
8 CVEs
30.8% of CVEs· 99th percentile
Nuclei
3 CVEs
11.5% of CVEs· 96th percentile
ExploitDB
12 CVEs
46.2% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nuuo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nuuo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nuuo's Products

View all 4 CNAs →

Top CWEs