{"id":"CVE-2026-88622","published":"2026-09-18T14:19:02.480","lastModified":"2026-09-22T20:00:03.713","description":"NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-77"],"vendors":[],"products":[],"references":[{"url":"http://nuuo.com","tags":[]},{"url":"https://gist.github.com/4o3-f0rb1dd3n/b03b435a7c6730a0c9586bcc7967d9b5","tags":[]}],"exploitRefs":[{"url":"https://gist.github.com/4o3-f0rb1dd3n/b03b435a7c6730a0c9586bcc7967d9b5","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows command injection in handle_import_privilege.php, enabling an attacker to execute arbitrary commands on the server.","exploitability":"Exploitation is relatively easy given the required user interaction, making it a high-risk vulnerability.","blast_radius":"If exploited, this could lead to complete server compromise, allowing attackers to gain full control over the system.","remediation":"Upgrade to the fixed version 2.0.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","command-injection","web","php"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:24:15.777Z"}}