CVE-2025-1338 is a critical command injection vulnerability in NUUO Camera, affecting versions up to 20250203. The flaw is in the print_file function within /handle_config.php, where the log argument is improperly handled. An attacker can manipulate this parameter to inject and execute arbitrary operating system commands. The issue is remotely exploitable, and public exploit details are available. The vendor reportedly did not respond to early disclosure attempts.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
/handle_config.php. Place affected devices behind VPNs or administrative jump hosts, enforce IP allowlisting, and block direct external access. Apply web filtering or reverse-proxy rules to detect and block suspicious requests targeting the log parameter. Monitor for exploitation attempts against /handle_config.php, unusual command execution, and anomalous outbound connections from camera systems. Given public exploit availability and active scanning, prioritize emergency containment for exposed devices.Patch, then assume compromise.
/handle_config.php and the issue is caused by unsafe handling of the log parameter in print_file, remediation requires vendor code changes that eliminate shell command construction from untrusted input or strictly validate and safely handle the parameter. If no patch is available, replace or isolate affected systems.No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the aggregated IOC CVE list without additional detail in the provided content.
A recent N-day vulnerability observed being exploited in parallel with CVE-2025-55182 by China-nexus threat activity; no additional technical details are provided in the content.
Unknown (mentioned only as another N-day targeted in broad multi-CVE campaigns; no technical details provided).
Unknown (mentioned only as another recent N-day vulnerability being exploited in parallel; no technical details provided).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.