CVE-2018-1150: NUUO NVRmini2 Firmware

High severity, CVSS 7.3. EPSS: 2.1% chance of exploitation in the next 30 days.

NUUO's NVRMini2 3.8.0 and below contains a backdoor that would allow an unauthenticated remote attacker to take over user accounts if the file /tmp/moses exists.

Affected products

  • NUUO NVRmini2 Firmware: up to and including 3.8.0

Published 2018-09-19. Last modified 2026-06-17.