/Vulnerability Library

NUUO Camera <=20250203 - OS Command Injection

CVE-2025-1338
Verified

Description

NUUO Camera up to 20250203 contains a command injection caused by manipulation of the 'log' argument in /handle_config.php, letting remote attackers execute arbitrary commands, exploit requires remote access.

Severity

Critical

Exploit Probability

51%

Published Date

February 11, 2026

Template Author

ark

CVE-2025-1338.yaml
9.5Severity

CVSS Metrics

CVE ID:
cve-2025-1338
CWE ID:
cwe-78

References

https://nvd.nist.gov/vuln/detail/CVE-2025-1338https://github.com/advisories/GHSA-vw58-vgp6-39qxhttps://dbugs.ptsecurity.com/vulnerability/CVE-2025-1338

Remediation Steps

Update to the latest version of NUUO Camera or apply security patches provided by the vendor.