CVE-2018-9995
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 82.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 82.61% probability · 100th percentile
- CISA KEV
- Not listed
- Affected
- tbkvision/tbk-dvr4216 firmware · tbkvision/tbk-dvr4104 firmware
- Source
- cve@mitre.org
References
- http://misteralfa-hack.blogspot.cl/2018/04/tbk-vision-dvr-login-bypass.htmlExploit, Third Party Advisory
- http://misteralfa-hack.blogspot.cl/2018/04/update-dvr-login-bypass-cve-2018-9995.htmlExploit, Third Party Advisory
- https://www.bleepingcomputer.com/news/security/new-hacking-tool-lets-users-access-a-bunch-of-dvrs-and-their-video-feeds/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/44577/Exploit, Third Party Advisory, VDB Entry
- http://misteralfa-hack.blogspot.cl/2018/04/tbk-vision-dvr-login-bypass.htmlExploit, Third Party Advisory
- http://misteralfa-hack.blogspot.cl/2018/04/update-dvr-login-bypass-cve-2018-9995.htmlExploit, Third Party Advisory
- https://www.bleepingcomputer.com/news/security/new-hacking-tool-lets-users-access-a-bunch-of-dvrs-and-their-video-feeds/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/44577/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.