PT-2026-95388 · Nuuo · Nuuo Network Video Recorder
CVE-2026-88623
·
Published
2026-09-18
·
Updated
2026-09-18
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NUUO Network Video Recorder version 2.0.0
Description
An arbitrary file read issue exists in the 'up.php' endpoint. The application receives the
url parameter via a POST request and uses the fopen() function to open the specified URL in binary read-only mode. The retrieved content is subsequently written to the /tmp/ directory, using a filename derived from the basename() of the URL. This process can be executed without authentication.Recommendations
Update NUUO Network Video Recorder version 2.0.0 to a newer version that addresses this issue.
As a temporary mitigation, restrict access to the 'up.php' endpoint or avoid using the
url parameter until a patch is applied.Exploit
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nuuo Network Video Recorder