EIP-2026-100868
PRE-CVENUUO NVRmini 2 3.0.8 - Remote Command Injection (Shellshock)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-100868. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a ShellShock vulnerability in NUUO NVRmini 2, allowing remote code execution via a crafted HTTP request with a malicious User-Agent header. The provided HTTP request triggers command execution (e.g., `/bin/ls -al`) and includes a successful response showing directory listing.
Description
NUUO NVRmini 2 3.0.8 - Remote Command Injection (Shellshock)
Exploits (1)
This exploit demonstrates a ShellShock vulnerability in NUUO NVRmini 2, allowing remote code execution via a crafted HTTP request with a malicious User-Agent header. The provided HTTP request triggers command execution (e.g., `/bin/ls -al`) and includes a successful response showing directory listing.