← back
CVE-2018-9995observed exploitation

CVE-2018-9995

90Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 83%
from disclosure to weapon0 days
Published on NVDApr 10
1st PoCMar 30
VulnCheck+686d
exploitation probability
83%top 1% of all CVEs
observed exploitation
yesVulnCheck
61 public exploit(s)
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.
Affected products
n/a · n/a
public PoCs found61
exploitdbwww.exploit-db.com/exploits/44577unverifiedgithubgithub.com/ezelf/CVE-2018-9995_dvr_credentials557githubgithub.com/Cyb0r9/DVR-Exploiter112githubgithub.com/0xDamian/CVE-2018-9995-rs97githubgithub.com/X3RX3SSec/DVR_Sploit11githubgithub.com/K3ysTr0K3R/CVE-2018-9995-EXPLOIT9githubgithub.com/zzh217/CVE-2018-9995_Batch_scanning_exp4githubgithub.com/kienquoc102/CVE-2018-9995-24githubgithub.com/wmasday/HTC3githubgithub.com/codeholic2k18/CVE-2018-99952githubgithub.com/Huangkey/CVE-2018-9995_check2githubgithub.com/gwolfs/CVE-2018-9995-ModifiedByGwolfs2githubgithub.com/Saeed22487/CVE-2018-99951githubgithub.com/b510/CVE-2018-9995-POC1githubgithub.com/ST0PL/DVRFaultNET1githubgithub.com/F7P-H4NN1B4L/CVE-2018-9995-DVR-Credentials-Extractor1githubgithub.com/MrAli-Code/CVE-2018-9995_dvr_credentials1githubgithub.com/mesutozsoycom/cve-2018-99951githubgithub.com/awesome-consumer-iot/HTC1githubgithub.com/TateYdq/CVE-2018-9995-ModifiedByGwolfs0githubgithub.com/likaifeng0/CVE-2018-9995_dvr_credentials-dev_tool0githubgithub.com/dearpan/cve-2018-99950githubgithub.com/LeQuocKhanh2K/Tool_Exploit_Password_Camera_CVE-2018-99950githubgithub.com/arminarab1999/CVE-2018-99950githubgithub.com/batmoshka55/CVE-2018-9995_dvr_credentials0githubgithub.com/dego905/Cam0githubgithub.com/A-Alabdoo/CVE-DVr0githubgithub.com/ABIZCHI/CVE-2018-9995_dvr_credentials0vulncheckvulncheck.com/xdb/8b058986f896unverifiedvulncheckvulncheck.com/xdb/2810d053aebeunverifiedvulncheckvulncheck.com/xdb/603350887945unverifiedvulncheckvulncheck.com/xdb/e4fb6b56ea43unverifiedvulncheckvulncheck.com/xdb/d76ef67bb972unverifiedvulncheckvulncheck.com/xdb/756c2260045cunverifiedvulncheckvulncheck.com/xdb/30d4b8dd270funverifiedcve_referencewww.exploit-db.com/exploits/44577/unverifiedvulncheckvulncheck.com/xdb/29a3ae830757unverifiedvulncheckvulncheck.com/xdb/0bb1e6df735bunverifiedvulncheckvulncheck.com/xdb/5febaf1762ecunverifiedvulncheckvulncheck.com/xdb/f3881ccb1207unverifiedvulncheckvulncheck.com/xdb/0e22848f3872unverifiedvulncheckvulncheck.com/xdb/b91da9616aaaunverifiedvulncheckvulncheck.com/xdb/dae161a6d981unverifiedvulncheckvulncheck.com/xdb/7535982dc418unverifiedvulncheckvulncheck.com/xdb/17d89816eb23unverifiedvulncheckvulncheck.com/xdb/3d97c3fdd793unverifiedvulncheckvulncheck.com/xdb/4a57e0a35093unverifiedvulncheckvulncheck.com/xdb/3ff318fa745aunverifiedvulncheckvulncheck.com/xdb/529a7cb5859aunverifiedvulncheckvulncheck.com/xdb/41fff1110aeeunverifiedvulncheckvulncheck.com/xdb/07eb5a6f90b8unverifiedvulncheckvulncheck.com/xdb/bec8edb6b35cunverifiedvulncheckvulncheck.com/xdb/949b3e250e13unverifiedvulncheckvulncheck.com/xdb/68e84da49d7dunverifiedvulncheckvulncheck.com/xdb/21e4191ff6f5unverifiedvulncheckvulncheck.com/xdb/7eaf338f4f14unverifiedvulncheckvulncheck.com/xdb/5dc52e1063aeunverifiedvulncheckvulncheck.com/xdb/83ea1106c0fcunverifiedvulncheckvulncheck.com/xdb/afb0039313e2unverifiedvulncheckvulncheck.com/xdb/02e5259eb5e5unverifiedvulncheckvulncheck.com/xdb/7368119491d0unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.