CVE-2018-15716

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
9
HIGH
Affected
1
PROJECT

Description

NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to execute OS commands as root.

Proof of Concepts
GitHubGitHub
1.25K