CVE-2026-88622
8.8NUUO · Network Video Recorder
The NUUO Network Video Recorder 2.0.0 is vulnerable to command injection via the handle_import_privilege.php file, potentially allowing unauthorized command execution on the host system.
Executive summary
The NUUO Network Video Recorder 2.0.0 contains a command injection vulnerability that could allow an attacker to execute arbitrary commands on the affected system.
Vulnerability
The application is susceptible to command injection within the handle_import_privilege.php script. This flaw allows an attacker to inject and execute system-level commands, bypassing intended application restrictions.
Business impact
The CVSS score of 8.8 reflects the high severity of this command injection vulnerability. Successful exploitation permits an attacker to take control of the recording hardware, potentially leading to unauthorized surveillance access, persistent system compromise, or the use of the device as a pivot point within the internal network.
Remediation
Immediate Action: Since no specific patch is mentioned, organizations should restrict network access to the NUUO Network Video Recorder, ensuring it is not exposed to the public internet.
Proactive Monitoring: Review device access logs for unusual administrative activity or attempts to access the handle_import_privilege.php endpoint.
Compensating Controls: Implement strict firewall rules to segment the video recording system from critical business infrastructure and monitor for anomalous outbound traffic from the device.
Exploitation status
Public Exploit Available: Yes (A published proof-of-concept exists, attributed to the research write-up linked in the references).
Analyst recommendation
Due to the lack of an official patch, the primary defense is to isolate the affected device from all untrusted networks. Organizations should contact the vendor directly for security guidance and monitor their security bulletins for future firmware releases.
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Analyst report updated
- Published in the daily brief high section