← volver
CVE-2025-34132

LILIN DVR Command Injection via NTPUpdate in dvr_box

CVSS 9.3 CRITICALEPSS 1.8%CWE-20CWE-78
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field in the NTPUpdate configuration. The web service at /z/zbin/dvr_box fails to properly sanitize input, allowing remote attackers to inject and execute arbitrary commands as root by supplying specially crafted XML data to the DVRPOST interface.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Merit LILIN · DVR Firmware

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →