Command Injection in NUUO Camera handle_config.php print_file
CVE-2025-1338 is a critical command injection vulnerability in NUUO Camera, affecting versions up to 20250203. The flaw is in the print_file function within /handle_config.php, where the log argument is improperly handled. An attacker can manipulate this parameter to inject and execute arbitrary operating system commands. The issue is remotely exploitable, and public exploit details are available. The vendor reportedly did not respond to early disclosure attempts.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
/handle_config.php. Place affected devices behind VPNs or administrative jump hosts, enforce IP allowlisting, and block direct external access. Apply web filtering or reverse-proxy rules to detect and block suspicious requests targeting the log parameter. Monitor for exploitation attempts against /handle_config.php, unusual command execution, and anomalous outbound connections from camera systems. Given public exploit availability and active scanning, prioritize emergency containment for exposed devices.Remediation
Patch, then assume compromise.
/handle_config.php and the issue is caused by unsafe handling of the log parameter in print_file, remediation requires vendor code changes that eliminate shell command construction from untrusted input or strictly validate and safely handle the parameter. If no patch is available, replace or isolate affected systems.Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Recent activity
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the aggregated IOC CVE list without additional detail in the provided content.
A recent N-day vulnerability observed being exploited in parallel with CVE-2025-55182 by China-nexus threat activity; no additional technical details are provided in the content.
Unknown (mentioned only as another N-day targeted in broad multi-CVE campaigns; no technical details provided).
Unknown (mentioned only as another recent N-day vulnerability being exploited in parallel; no technical details provided).
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.