CVE-2022-23227: NUUO NVRmini2 Devices Missing Authentication Vulnerability
NUUO NVRmini2 Devices Missing Authentication Vulnerability . NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.
- CISA KEV-listed (remediation due 2025-01-08)
- EPSS 53.9% (98.1% percentile)