Back to Database
Status published
Critical
CVE-2016-5678
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0...
Vulnerability Description
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-5678
Credits & Attribution
No credits recorded in the NVD database.
References
More from nuuo
View All →CVE-2022-33119
NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain...
Medium
6.1
CVE-2022-25521
NUUO v03.11.00 was discovered to contain access control issue....
Critical
9.8
CVE-2022-23227
NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload...
Unknown
0
CVE-2021-45812
NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a...
Medium
6.1
CVE-2019-9653
NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated...
Critical
9.8
Affected Vendor
nuuo
View all reports →Affected Software
nvrmini 2, nvrsolo
Vulnerable Versions:
1.0.0, 1.1.0, 1.3.0, 1.3.2, 1.4.0, 1.5.1, 1.5.2, 1.6.0, 1.6.1, 1.6.2, 1.6.4, 1.7.0, 1.7.1, 1.7.2, 1.7.5, 1.7.6, 2.0.0, 2.2.1, 3.0.0, 1.0.1, 1.1.0.117, 1.1.1, 1.1.2, 1.2.0, 1.75, 2.0.1, 2.1.5, 2.2.2, 2.3, 2.3.1.20, 2.3.7.9, 2.3.7.10, 2.3.9.6
Timeline
Official Publish:
August 31st, 2016
Last Modified:
August 6th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.