漏洞描述 Dahua Security DVRAppliances利用瘦客户端如PSS,移动客户端接口如iDMSS和ActiveX控件"webrec.cab"进行访问。这些客户端与管理服务(TCP37777)进行通信。其中服务器没有正确校验ActiveX控件所提交的命令,允许攻击者利用漏洞绕过验证进行授权操作,获取敏感信息,更改用户密码等。
相关漏洞推荐 CVE-2018-9995: DVR Authentication Bypass POC 2025-09-01 | DVR DVR,全称为Digital Video Recorder(硬盘录像机),即数字视频录像机。最初由阿根廷研究员发现,通过使用“Cookie: uid = admin”的Cookie标头来访问特定DVR... avtech-dvr-exposure: Avtech AVC798HA DVR Information Exposure POC 2025-09-01 | Avtech DVR Under the /cgi-bin/nobody folder every CGI script can be accessed without authentication. app="... CVE-2018-15745: Argus Surveillance DVR 4.0.0.0 - Local File Inclusion POC 2025-08-01 | Argus Surveillance DVR Argus Surveillance DVR 4.0.0.0 devices allow unauthenticated local file inclusion, leading to file d... CVE-2013-1965: Apache Struts2 S2-012 RCE POC 2025-09-01 | Apache Struts2 Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote ... CVE-2013-2251: Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution (S2-016) POC 2025-09-01 | Apache Struts 2 In Struts 2 before 2.3.15.1 the information following "action:", "redirect:", or...