漏洞描述 DVR,全称为Digital VideoRecorder(硬盘录像机),即数字视频录像机,相对于传统的模拟摄像录像机,采⽤硬盘录像,故常常被称为硬盘录像机,也被称为DVR。漏洞影响文件device.rsp 允许未经授权的攻击者使用mdc参数进行命令注入。
相关漏洞推荐 Ilevia EVE X1 Server /ajax/php/leaf_replace_device.php 命令执行漏洞 POC CVE-2021-41419: QVIS NVR/DVR - Remote Code Execution POC CVE-2018-15745: Argus Surveillance DVR 4.0.0.0 - Local File Inclusion POC CVE-2018-9995: TBK DVR4104/DVR4216 Devices - Authentication Bypass POC CVE-2021-42071: Visual Tools DVR VX16 4.2.28.0 - Unauthenticated OS Command Injection POC CVE-2024-7339: TVT DVR Sensitive Device - Information Disclosure POC CVE-2018-9995: DVR Authentication Bypass POC CVE-2021-33044: Dahua IPC/VTH/VTO devices Authentication Bypass POC avtech-dvr-exposure: Avtech AVC798HA DVR Information Exposure POC huawei-dg8045-home-gateway-password-leakage: Huawei DG8045 deviceinfo 信息泄漏漏洞 POC device-guard-not-configured: Device Guard Not Configured POC CVE-2013-4982: AVTECH DVR - Login Verification Code Bypass POC avtech-dvr-exposure: AVTECH AVC798HA DVR - Information Exposure