Vulnerability record · CVE-2022-23227 · published 14 January 2022
CVE-2022-23227: NUUO NVRmini2 missing authentication allows unauthenticated user upload and root code execution
Nuuo · Nvrmini2 Firmware
NUUO NVRmini2 firmware through 3.11 fails to authenticate handle_import_user.php, letting an unauthenticated attacker upload an encrypted TAR archive that adds arbitrary users. Chained with CVE-2011-5325, this allows overwriting files under the web root and executing code as root.
Description
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable flaw with public exploits, KEV listing and near-top EPSS percentile, and the product is end-of-life with no supported fix.
What it is
NUUO NVRmini2 firmware through 3.11 fails to authenticate handle_import_user.php, letting an unauthenticated attacker upload an encrypted TAR archive that adds arbitrary users. Chained with CVE-2011-5325, this allows overwriting files under the web root and executing code as root.
Impact
An attacker gains full administrative control of the device, including the ability to add users and run code as root. That yields complete compromise of confidentiality, integrity and availability of the NVR.
Attack surface
Reachable over the network via the web interface with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any host that can reach the device's HTTP service can attempt it.
Exploitation
CISA added it to KEV on 2024-12-18 with a 2025-01-08 remediation due date, and public exploit references exist, including a Metasploit pull request. EPSS is 0.48497 (98.8th percentile), indicating high likelihood of exploitation activity.
What to do
- Discontinue use of NUUO NVRmini2 devices, which CISA lists as end-of-life/end-of-service; migrate to a supported product.
- If the device must remain temporarily, isolate it on a segmented network with no internet exposure and restrict management access to trusted hosts.
- Block or filter access to handle_import_user.php and the web interface at the network boundary until replacement.
- Monitor for unauthorized user additions and unexpected files under the web root as compensating controls.
- Apply any vendor-provided firmware update if one exists, but do not rely on it given the EoL status.
Detection
- Audit NVRmini2 user accounts for unexpected or newly created users, especially administrator accounts.
- Inspect the web root and filesystem for unexpected files or modified content that could indicate archive extraction or overwrite.
- Monitor HTTP requests to handle_import_user.php and for TAR archive uploads to the device.
- Alert on outbound or lateral network activity from NVR devices, which should not initiate such connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-23227 to the Known Exploited Vulnerabilities catalog on 18 December 2024 as "NUUO NVRmini2 Devices Missing Authentication Vulnerability ". Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product. Federal deadline 8 January 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/pedrib/PoC/blob/master/advisories/NUUO/nuuo_nvrmini_round2.mkd | ExploitThird Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/16044 | ExploitIssue TrackingThird Party Advisory |
| https://news.ycombinator.com/item?id=29936569 | Third Party Advisory |
| https://portswigger.net/daily-swig/researcher-discloses-alleged-zero-day-vulnerabilities-in-nuuo-nvrmini2-recording-devi | ExploitThird Party Advisory |
| https://github.com/pedrib/PoC/blob/master/advisories/NUUO/nuuo_nvrmini_round2.mkd | ExploitThird Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/16044 | ExploitIssue TrackingThird Party Advisory |
| https://news.ycombinator.com/item?id=29936569 | Third Party Advisory |
| https://portswigger.net/daily-swig/researcher-discloses-alleged-zero-day-vulnerabilities-in-nuuo-nvrmini2-recording-devi | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-23227 | US Government Resource |
Track CVE-2022-23227 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23227), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.