Loading
cgi_system in NUUO's NVRMini2 3.8.0 and below allows remote attackers to execute arbitrary code via crafted HTTP requests.
Use CWE-119, Nuuo vendor hub and Nvrmini2 Firmware product page to widen CVE-2018-1149 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-23227, CVE-2018-19864 and CVE-2018-15716 for nearby disclosures in the same product family.