LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-14933: NUUO NVRmini Devices OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 18, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 8, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-14933 to its Known Exploited Vulnerabilities catalog on Dec 18, 2024, with a federal patch deadline of Jan 8, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

CVE-2018-14933 is an OS command injection flaw in NUUO NVRmini devices that lets a remote attacker run arbitrary commands on the underlying system. Because these devices often sit on networks that handle video surveillance feeds and may have weak segmentation, successful abuse can give an attacker a foothold for further movement or data access. The product is end-of-life and end-of-service, so the only durable fix is to stop using it.

How it works

The weakness is classified as CWE-78 (OS Command Injection). According to the CISA summary, an attacker can inject shell metacharacters into the uploaddir parameter of a writeuploaddir command. When the device processes that input without proper sanitization, the injected characters are interpreted by the operating-system shell, resulting in remote command execution. No further exploit mechanics are required for understanding: any unauthenticated or low-privilege request that reaches the vulnerable parameter can be turned into system-level commands. Exact request formats and payloads must be confirmed against the original vendor advisory if it is still available.

Am I affected? How to find it in your systems

NUUO NVRmini appliances are network video recorders commonly deployed for CCTV and IP-camera storage. They typically appear as dedicated hardware appliances or embedded Linux systems listening on HTTP/HTTPS management ports and RTSP/streaming ports.

Confirm any version or build identifiers against the vendor’s last published advisory, as public detail is limited.

How to remediate

CISA’s required action is unambiguous: the impacted product is end-of-life and/or end-of-service. Users should discontinue utilization of the product. There is no vendor patch path once a device reaches EoL/EoS status.

If you can't patch immediately

Because no patch exists, focus on isolation and detection until the device can be retired.

These measures reduce exposure but do not eliminate the underlying risk; replacement remains the only complete remediation.

If your data may have been exposed

Actively exploited command-injection vulnerabilities on network appliances frequently lead to broader compromise. If logs or other indicators suggest the device was reached by an attacker, assume credentials, video archives, or adjacent systems may have been accessed. Rotate any passwords or certificates that were stored on or used by the NVRmini, and review connected camera and storage systems for signs of lateral movement. Readers can also run a free exposure scan of their email addresses against known breach data sets to determine whether associated accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedNUUO · NVRmini Devices
WeaknessCWE-78
Added to CISA KEVDec 18, 2024
Federal patch deadlineJan 8, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities