OpsBuzz

Alert

NUUO NVRmini2 Devices Missing Authentication Vulnerability

NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can

Security · HIGH
Source: CISA Known Exploited VulnerabilitiesMay 2, 2026, 4:51 PMSecurityhigh

Full content

NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.

Vendor: NUUO

Product: NVRmini2 Devices

Due date: 2025-01-08

Known ransomware use: Unknown

Why it matters

The impacted product is end-of-life EoL and/or end-of-service EoS . Users should discontinue utilization of the product.

Related alerts

NUUO NVRmini2 Devices Missing Authentication Vulnerability | OpsBuzz