Vulnerabilities > Nuuo > Nvrmini2 Firmware > 3.11.0

DATE CVE VULNERABILITY TITLE RISK
2022-01-14 CVE-2022-23227 Missing Authentication for Critical Function vulnerability in Nuuo Nvrmini2 Firmware
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication.
network
low complexity
nuuo CWE-306
critical
9.8