← volver
CVE-2025-34132

LILIN DVR Command Injection via NTPUpdate in dvr_box

CVSS 9.3 CRITICALEPSS 1.8%CWE-20CWE-78
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.3EPSS 1.8%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
16 jul 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field in the NTPUpdate configuration. The web service at /z/zbin/dvr_box fails to properly sanitize input, allowing remote attackers to inject and execute arbitrary commands as root by supplying specially crafted XML data to the DVRPOST interface.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Merit LILIN · DVR Firmware

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →