Skip to main content
Mallory
Medium

Command Injection in NUUO Camera handle_config.php print_file

IdentifiersCVE-2025-1338CWE-78

CVE-2025-1338 is a critical command injection vulnerability in NUUO Camera, affecting versions up to 20250203. The flaw is in the print_file function within /handle_config.php, where the log argument is improperly handled. An attacker can manipulate this parameter to inject and execute arbitrary operating system commands. The issue is remotely exploitable, and public exploit details are available. The vendor reportedly did not respond to early disclosure attempts.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows remote execution of arbitrary OS commands in the context of the vulnerable NUUO Camera application. This can enable full compromise of the device or underlying host, including unauthorized access to files, execution of follow-on payloads, persistence, and potential use of the system as a foothold for further network activity. The content also indicates the vulnerability has been incorporated into broader opportunistic scanning and exploitation campaigns targeting unpatched internet-exposed systems.

Mitigation

If you can’t patch tonight, do this now.

Restrict network access to NUUO Camera management interfaces, especially any internet exposure to /handle_config.php. Place affected devices behind VPNs or administrative jump hosts, enforce IP allowlisting, and block direct external access. Apply web filtering or reverse-proxy rules to detect and block suspicious requests targeting the log parameter. Monitor for exploitation attempts against /handle_config.php, unusual command execution, and anomalous outbound connections from camera systems. Given public exploit availability and active scanning, prioritize emergency containment for exposed devices.

Remediation

Patch, then assume compromise.

Upgrade NUUO Camera to a vendor-fixed release newer than version 20250203 if one is available. Because the vulnerable component is /handle_config.php and the issue is caused by unsafe handling of the log parameter in print_file, remediation requires vendor code changes that eliminate shell command construction from untrusted input or strictly validate and safely handle the parameter. If no patch is available, replace or isolate affected systems.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence4

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures2

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity8

Community discussion across Reddit, Mastodon, and other social sources.