CVE-2018-1149

cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP requests.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nuuo:nvrmini2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:nuuo:nvrmini2:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-09-19 15:29

Updated : 2024-02-04 20:03


NVD link : CVE-2018-1149

Mitre link : CVE-2018-1149

CVE.ORG link : CVE-2018-1149


JSON object : View

Products Affected

nuuo

  • nvrmini2
  • nvrmini2_firmware
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer