CVE-2018-19864: NUUO NVRmini2 Firmware

Critical severity, CVSS 9.8. EPSS: 24.8% chance of exploitation in the next 30 days.

NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device.

Affected products

  • NUUO NVRmini2 Firmware: up to and including 3.9.1

Published 2018-12-05. Last modified 2026-06-17.