CVE-2018-14933: NUUO NVRmini Devices OS Command Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-12-18. EPSS: 94.8% chance of exploitation in the next 30 days.

upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

Affected products

  • NUUO NVRmini Firmware: version 2016 only

Published 2018-08-04. Last modified 2026-06-17.