peter bassill · operator
$ cve CVE-2018-9995 JSON

CVE-2018-9995 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 82.3% (pctl 100)

Patch early

A public exploit exists.

Description

TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS82.32% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2018-04-10
Last modified2026-06-17

Affected (4)

VendorProduct
tbkvisiontbk-dvr4104
tbkvisiontbk-dvr4104 firmware
tbkvisiontbk-dvr4216
tbkvisiontbk-dvr4216 firmware

Public exploits

SourceTitleDate
exploit-dbTBK DVR4104 / DVR4216 - Credentials Leak2018-05-02

References

→ the Explorer  ·  watch your stack  ·  NVD