A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2022-23227

NUUO NVRmini2 Devices Missing Authentication Vulnerability

Published
2024-12-18
Modified
2026-07-31
Sources
cisa-kev

Summary

NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.