CVE-2019-9653: NUUO Network Video Recorder Firmware

Critical severity, CVSS 9.8. EPSS: 11.5% chance of exploitation in the next 30 days.

NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands via shell metacharacters to handle_load_config.php.

Affected products

  • NUUO Network Video Recorder Firmware: from 1.7.0, up to and including 3.3.0

Published 2019-05-31. Last modified 2026-06-17.