Security Advisory

CVE-2018-15716

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-11-30 20:00:00
Last updated 2024-09-16 17:28:51
Assigner tenable
CVSS score not scored
State PUBLISHED

Description

NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to execute OS commands as root.