Horizon Alert
Summary of the vulnerability and why it matters
The NUUO NVRmini2 through version 3.11 is vulnerable to an unauthenticated attacker. This vulnerability allows an attacker to upload an encrypted TAR archive, leading to the addition of arbitrary users. If combined with another flaw, this can result in the overwriting of files and code execution with root privileges.
- Vulnerable component: NUUO NVRmini2 firmware
- Core weakness: Missing authentication for user import
- Main business impact: Unauthorized user access and code execution
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit a vulnerability in NUUO NVRmini2 devices. This allows the attacker to upload a specially crafted archive. By combining this with another flaw, the attacker can gain the ability to overwrite arbitrary files and execute code with root privileges. This could lead to a complete compromise of the affected device and potential lateral movement within the network.
- Publicly accessible NVRmini2 devices.
- Attacker uploads malicious archive.
- Attacker achieves code execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability presents a significant risk due to its high exploitability and potential for severe damage. Attackers with moderate technical skill could exploit this flaw to gain unauthorized access, add administrative users, and ultimately execute arbitrary code on affected systems. This could lead to complete system compromise and potential data theft or manipulation. Given the severity and ease of exploitation, treating this vulnerability with high urgency is recommended.
- Likely attacker skill level: Moderate
- Required access or conditions: Unauthenticated network access
- Business risk or urgency: High
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects NUUO NVRmini2 devices, allowing unauthenticated attackers to upload malicious archives. This can lead to the addition of arbitrary users and the potential for code execution with root privileges. The vendor has indicated the affected product is end-of-life and end-of-service. Organizations should cease using this product.
- Identify NUUO NVRmini2 devices.
- Discontinue use of the product.
- Verify product removal.