← voltar
CVE-2025-34132criticalexploração observadaCWE-20CWE-78

LILIN DVR Command Injection via NTPUpdate in dvr_box

50Vexday Risk Score

Priorize a correção. Ela exploração observada pelo VulnCheck.

ssvc Actcvss 9.3epss 1.7%
da publicação à arma
Publicada no NVD16 de jul.
VulnCheck20 de mar.
probabilidade de exploração
1.7%top 24% das CVEs
exploração observada
simVulnCheck
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field in the NTPUpdate configuration. The web service at /z/zbin/dvr_box fails to properly sanitize input, allowing remote attackers to inject and execute arbitrary commands as root by supplying specially crafted XML data to the DVRPOST interface.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N