Peekaboo: Tenable Research has discovered a pair of vulnerabilities in NUUO's Video Recorder Software that allow attackers to execute remote code on NUUO-based IoT video surveillance systems, providing access to video feeds and recordings.
This specific remote code execution vulnerability is called Peekaboo.
The first vulnerability of the pair found in NUUO's Network Video Recorder software is a critical stack buffer overflow, while the second consists of a backdoor in leftover debug code.
Both vulnerabilities were evaluated and tested on the lightweight and portable NVRMini2 NVR with NAS functionality and are considered extremely critical as they could provide attackers with full access to the system.

NUUO's video recording software features thousands of cameras from over 100 vendors.
Once hackers have full access to the NVRMini2, they can view all camera feeds or video recordings accessible from the compromised device, with the added benefit of accessing the credentials of all connected devices.
The biggest problem is that NUUO 's video recording software is also available as a control tool for more than 100 different surveillance camera manufacturers, which seriously expands the threat range of the vulnerability described in the Tenable Research report.
NUUO, for its part, was given 105 days to release a patch for the exploited software. Nevertheless, the company managed to prepare it after the event was made public.
