NUUO Cameras are network-connected video recording and surveillance devices commonly used for physical security monitoring in corporate and industrial environments. Their role in providing critical visual surveillance means that a compromise can have severe real-world consequences, effectively blinding an organization’s security setup.
The impact of this vulnerability is a complete system compromise by an unauthenticated remote attacker. This allows an adversary to gain full control of the device without the need for prior access or credentials. The risk is particularly high for NUUO cameras exposed directly to the internet.
A public exploit for this vulnerability has been disclosed, making the probability of widespread and active exploitation extremely high. Attackers can use automated scans to locate and compromise vulnerable devices at scale. A compromised camera can be used to exfiltrate sensitive video streams, serve as an entry point into the internal corporate network, or be assimilated into a botnet for DDoS attacks.
| Product | NUUO Camera |
| Date | 2025-12-05 12:27:14 |
Technical Summary
The vulnerability is a classic command injection flaw, identified as CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’). It is present in the firmware of NUUO Camera devices.
The root cause is the lack of input sanitization in the handle_config.php script. Specifically, the print_file function accepts a user-controlled parameter called log. The value of this parameter is passed directly to a system-level command without being validated or sanitized for shell metacharacters.
The attack chain is as follows:
- An unauthenticated remote attacker sends a specially crafted HTTP request to the
/handle_config.phpendpoint. - The attacker embeds arbitrary operating system commands within the
logparameter, using shell metacharacters such as the semicolon (;) or backticks (`) to concatenate commands. - The backend
print_filefunction concatenates the maliciouslogparameter into a string that is then executed by the underlying operating system.
A conceptual representation of the vulnerable code logic is:
<?php
// /handle_config.php
function print_file($filename) {
// The value of $_GET["log"] is passed directly to a shell command
// without sanitization, allowing for command injection.
system("print " . $filename);
}
$log_file = $_GET["log"];
print_file($log_file);
?>
Vulnerable versions:
- NUUO Camera firmware versions up to and including 20250203 are vulnerable.
Fix availability:
- There is currently no official patch available from the vendor.
Recommendations
- Disable or isolate immediately: Since there is no official patch, the primary recommendation is to immediately decommission and replace the affected NUUO Camera devices. If immediate replacement is not possible, the device must be disconnected from any untrusted network, especially the internet.
- Network-level mitigation: If the device must remain operational on an internal network, restrict access to its web interface (typically ports 80/443) to a dedicated, trusted management VLAN. Use a Web Application Firewall (WAF) or a reverse proxy to create a rule that explicitly denies any requests to the
/handle_config.phpendpoint. - Compromise detection and monitoring:
- Analyze web server access logs on the devices or upstream network appliances for any requests to
/handle_config.php. - Examine these logs for suspicious characters or command strings within the
logparameter (e.g.,;,|,wget,curl,nc). - Monitor network traffic for unexpected outbound connections originating from camera devices, which could indicate command and control (C2) communications.
- Analyze web server access logs on the devices or upstream network appliances for any requests to
- Incident response: If a device is found to have been exposed and a compromise is suspected, assume a breach. Immediately isolate the device from the network to prevent lateral movement and begin a forensic analysis. The device could serve as a foothold for deeper intrusion into the corporate network.
- Defense in depth: This vulnerability highlights the critical importance of network segmentation. IoT and OT devices, such as security cameras, should never reside on the same network segment as critical servers or user workstations.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
