CVE-2016-20016
CVE-2016-20016
Vexday Risk Score
85Fix now
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 86.3%KEV nãoPoC públicaNuclei —Metasploit simPatch —
Lifecycle
23 Aug 2015Metasploit module available
19 Oct 2022Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerability has also been referred to as the "JAWS webserver RCE" because of the easily identifying HTTP response server field. Other firmware versions, at least from 2014 through 2019, can be affected. This was exploited in the wild in 2017 through 2022.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/41471unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →