漏洞标题
NUUO Camera handle_config.php print_file 命令注入漏洞
漏洞描述信息
在NUUO Camera版本20250203及之前版本中发现了一个漏洞,该漏洞被评估为关键等级。此漏洞影响文件/handle_config.php中的print_file函数。通过操控参数log可以导致命令注入。该攻击可以远程发起。该漏洞的利用方法已经公开,可能会被利用。已提前联系厂商通报此漏洞,但厂商未做出任何回应。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
在命令中使用的特殊元素转义处理不恰当(命令注入)
漏洞标题
NUUO Camera handle_config.php print_file command injection
漏洞描述信息
A vulnerability was found in NUUO Camera up to 20250203. It has been declared as critical. This vulnerability affects the function print_file of the file /handle_config.php. The manipulation of the argument log leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
漏洞类别
在命令中使用的特殊元素转义处理不恰当(命令注入)