← Browse

CVE-2018-14933

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
94.9%
99.9th percentile
CISA KEV
Listed
Added 2024-12-18 · patch by 2025-01-08
Weakness / dates
Published — · modified —

Timeline

Description

NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

Official: NVD · CVE.org