This vulnerability (with proof of concept (PoC) code) affects DVR/NVR devices built using the HiSilicon hi3520d and similar system on a chip (SoC).
Exploiting the vulnerabilities lead to unauthorized remote code execution (RCE) using only the web interface, causing full takeover of the exploited device
Severity: high
Fingerprint: 321975614123c6c05f83e99b29a4a388ea09eeadea09eeadea09eeadea09eead
Found HiSiliconDVR firmware: Hardware: General MBD6508E Vulnerable to multiple issues : LFI, possibly RCE
Open service 106.1.112.163:80
2024-09-15 19:58
HTTP/1.1 200 OK Content-type: text/html Content-Length: 1937 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Connection: close <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title></title> <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" media="screen" /> </head> <body> <div class="loadingIndicator_bk"> </div> <div class="loadingIndicator_tip"> <div style="height: 300px;"> </div> <span class="msg_border"><span class="msg"></span></span> </div> <div id="InitialView" style="background: #fff center url(css/Pictures/initview.gif) no-repeat; width: 100%; height: 100%;"></div> <div id="BaseContent"> </div> <!----> <div id="topFloatMsg"> <div id="topFloatMsg_title"> </div> <div id="topFloatMsg_body"> <div id="topFloatMsg_icon"> </div> <div id="topFloatMsg_content"> </div> </div> <div id="topFloatMsg_bottom"> </div> </div> <iframe id="topFloatMsg_bk" scrolling="no" frameborder="0" src="about:blank"></iframe> <!----> <div id="topRollMsg"> <div id="topRollMsg_title"> <span lc="html" lk="IDCS_INFO_TIP"></span> <div id="topRollMsg_close"> </div> </div> <div id="topRollMsg_content"> </div> </div> <iframe id="topRollMsg_bk" width="100%" height="100%" scrolling="no" frameborder="0" src="about:blank"></iframe> <script language="javascript" for="VideoPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> VideoPluginNotify(strXMLFormat, lStrLen); </script> <script language="javascript" for="TimeSliderPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> TimeSliderPluginNotify(strXMLFormat, lStrLen); </script> <script data-main="js/index.js?v=20221111.01" src="js/lib/require.js" type="text/javascript"></script> </body> </html>
Open service 106.1.112.163:80
2024-09-13 19:57
HTTP/1.1 200 OK Content-type: text/html Content-Length: 1937 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Connection: close <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title></title> <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" media="screen" /> </head> <body> <div class="loadingIndicator_bk"> </div> <div class="loadingIndicator_tip"> <div style="height: 300px;"> </div> <span class="msg_border"><span class="msg"></span></span> </div> <div id="InitialView" style="background: #fff center url(css/Pictures/initview.gif) no-repeat; width: 100%; height: 100%;"></div> <div id="BaseContent"> </div> <!----> <div id="topFloatMsg"> <div id="topFloatMsg_title"> </div> <div id="topFloatMsg_body"> <div id="topFloatMsg_icon"> </div> <div id="topFloatMsg_content"> </div> </div> <div id="topFloatMsg_bottom"> </div> </div> <iframe id="topFloatMsg_bk" scrolling="no" frameborder="0" src="about:blank"></iframe> <!----> <div id="topRollMsg"> <div id="topRollMsg_title"> <span lc="html" lk="IDCS_INFO_TIP"></span> <div id="topRollMsg_close"> </div> </div> <div id="topRollMsg_content"> </div> </div> <iframe id="topRollMsg_bk" width="100%" height="100%" scrolling="no" frameborder="0" src="about:blank"></iframe> <script language="javascript" for="VideoPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> VideoPluginNotify(strXMLFormat, lStrLen); </script> <script language="javascript" for="TimeSliderPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> TimeSliderPluginNotify(strXMLFormat, lStrLen); </script> <script data-main="js/index.js?v=20221111.01" src="js/lib/require.js" type="text/javascript"></script> </body> </html>
Open service 106.1.112.163:80
2024-09-11 20:17
HTTP/1.1 200 OK Content-type: text/html Content-Length: 1937 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Connection: close <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title></title> <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" media="screen" /> </head> <body> <div class="loadingIndicator_bk"> </div> <div class="loadingIndicator_tip"> <div style="height: 300px;"> </div> <span class="msg_border"><span class="msg"></span></span> </div> <div id="InitialView" style="background: #fff center url(css/Pictures/initview.gif) no-repeat; width: 100%; height: 100%;"></div> <div id="BaseContent"> </div> <!----> <div id="topFloatMsg"> <div id="topFloatMsg_title"> </div> <div id="topFloatMsg_body"> <div id="topFloatMsg_icon"> </div> <div id="topFloatMsg_content"> </div> </div> <div id="topFloatMsg_bottom"> </div> </div> <iframe id="topFloatMsg_bk" scrolling="no" frameborder="0" src="about:blank"></iframe> <!----> <div id="topRollMsg"> <div id="topRollMsg_title"> <span lc="html" lk="IDCS_INFO_TIP"></span> <div id="topRollMsg_close"> </div> </div> <div id="topRollMsg_content"> </div> </div> <iframe id="topRollMsg_bk" width="100%" height="100%" scrolling="no" frameborder="0" src="about:blank"></iframe> <script language="javascript" for="VideoPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> VideoPluginNotify(strXMLFormat, lStrLen); </script> <script language="javascript" for="TimeSliderPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> TimeSliderPluginNotify(strXMLFormat, lStrLen); </script> <script data-main="js/index.js?v=20221111.01" src="js/lib/require.js" type="text/javascript"></script> </body> </html>
Open service 106.1.112.163:80
2024-09-09 19:54
HTTP/1.1 200 OK Content-type: text/html Content-Length: 1937 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Connection: close <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title></title> <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" media="screen" /> </head> <body> <div class="loadingIndicator_bk"> </div> <div class="loadingIndicator_tip"> <div style="height: 300px;"> </div> <span class="msg_border"><span class="msg"></span></span> </div> <div id="InitialView" style="background: #fff center url(css/Pictures/initview.gif) no-repeat; width: 100%; height: 100%;"></div> <div id="BaseContent"> </div> <!----> <div id="topFloatMsg"> <div id="topFloatMsg_title"> </div> <div id="topFloatMsg_body"> <div id="topFloatMsg_icon"> </div> <div id="topFloatMsg_content"> </div> </div> <div id="topFloatMsg_bottom"> </div> </div> <iframe id="topFloatMsg_bk" scrolling="no" frameborder="0" src="about:blank"></iframe> <!----> <div id="topRollMsg"> <div id="topRollMsg_title"> <span lc="html" lk="IDCS_INFO_TIP"></span> <div id="topRollMsg_close"> </div> </div> <div id="topRollMsg_content"> </div> </div> <iframe id="topRollMsg_bk" width="100%" height="100%" scrolling="no" frameborder="0" src="about:blank"></iframe> <script language="javascript" for="VideoPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> VideoPluginNotify(strXMLFormat, lStrLen); </script> <script language="javascript" for="TimeSliderPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> TimeSliderPluginNotify(strXMLFormat, lStrLen); </script> <script data-main="js/index.js?v=20221111.01" src="js/lib/require.js" type="text/javascript"></script> </body> </html>
Open service 106.1.112.163:80
2024-09-07 19:54
HTTP/1.1 200 OK Content-type: text/html Content-Length: 1937 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Connection: close <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title></title> <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" media="screen" /> </head> <body> <div class="loadingIndicator_bk"> </div> <div class="loadingIndicator_tip"> <div style="height: 300px;"> </div> <span class="msg_border"><span class="msg"></span></span> </div> <div id="InitialView" style="background: #fff center url(css/Pictures/initview.gif) no-repeat; width: 100%; height: 100%;"></div> <div id="BaseContent"> </div> <!----> <div id="topFloatMsg"> <div id="topFloatMsg_title"> </div> <div id="topFloatMsg_body"> <div id="topFloatMsg_icon"> </div> <div id="topFloatMsg_content"> </div> </div> <div id="topFloatMsg_bottom"> </div> </div> <iframe id="topFloatMsg_bk" scrolling="no" frameborder="0" src="about:blank"></iframe> <!----> <div id="topRollMsg"> <div id="topRollMsg_title"> <span lc="html" lk="IDCS_INFO_TIP"></span> <div id="topRollMsg_close"> </div> </div> <div id="topRollMsg_content"> </div> </div> <iframe id="topRollMsg_bk" width="100%" height="100%" scrolling="no" frameborder="0" src="about:blank"></iframe> <script language="javascript" for="VideoPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> VideoPluginNotify(strXMLFormat, lStrLen); </script> <script language="javascript" for="TimeSliderPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> TimeSliderPluginNotify(strXMLFormat, lStrLen); </script> <script data-main="js/index.js?v=20221111.01" src="js/lib/require.js" type="text/javascript"></script> </body> </html>
Open service 106.1.112.163:80
2024-08-17 22:11
HTTP/1.0 200 OK Content-type: text/html Server: uc-httpd 1.0.0 Expires: 0 Page title: NETSurveillance WEB <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /> <link rel="stylesheet" type="text/css" media="screen" href="m.css" /> <title>NETSurveillance WEB</title> <!-- m.js --> <script type="text/javascript" language="JavaScript"> if(navigator.userAgent.indexOf('IE') < 0) { var userAgent = navigator.userAgent, rMsie = /(msie\s|trident.*rv:)([\w.]+)/, rFirefox = /(firefox)\/([\w.]+)/, rOpera = /(opera).+version\/([\w.]+)/, rChrome = /(chrome)\/([\w.]+)/, rSafari = /version\/([\w.]+).*(safari)/; var browserMatch = uaMatch(userAgent.toLowerCase()); if(browserMatch.browser!="IE") { location="Login.htm"; } } function uaMatch(ua) { var match = rMsie.exec(ua); if (match != null) { return { browser : "IE", version : match[2] || "0" }; } var match = rFirefox.exec(ua); if (match != null) { return { browser : match[1] || "", version : match[2] || "0" }; } var match = rOpera.exec(ua); if (match != null) { return { browser : match[1] || "", version : match[2] || "0" }; } var match = rChrome.exec(ua); if (match != null) { return { browser : match[1] || "", version : match[2] || "0" }; } var match = rSafari.exec(ua); if (match != null) { return { browser : match[2] || "", version : match[1] || "0" }; } if (match != null) { return { browser : "", version : "0" }; } } </script> <script type="text/javascript">//m.js var ipaddress =document.location.hostname; if (ipaddress == "") { // ipaddress = "10.10.48.46"; // ipaddress = "10.2.2.88"; } var hostport=34567; var iLanguage=102; var numLanguage; var DownLoadAddr=""; </script> <script type="text/javascript" src="m.jsp"></script> <script type="text/javascript" src="config.js"></script> <!-- 全局变量 --> <script type="text/javascript"> var gExitChannel=new Array(); var gExitSubType=new Array(); var gexiti; var gcid=-1; var g_channelNum=4; var g_digitalChannel=0; var gsld; var gslda; var gsldb; var gsldc; var gsldd; var gfmu1=0; var gfmu2=0; var gfmu3=0; var g_bRecord=false; var g_bRealPlay=false; var g_bAudio=false; var g_bQS=false; var g_bClose=false; var gHashCookie = new Hash.Cookie('NetSuveillanceWebCookie',{duration: 30}); var settings = { username:'', ocxlanguage:'' } var gca=0; var gcb=0; var gcc=0; var gcd=0; var gAutoPlayAll=false; </script> <!-- 颜色滑块 --> <script type="text/javascript"> function sldtopos(sld,step){ sld.knob.setStyle('left', sld.toPosition(step)); } function setcolorsv(f,v){ switch (f) { case 1: gca=v; $('ska').title=v; break; case 2: gcb=v; $('skb').title=v; break; case 3: gcc=v; $('skc').title=v; break; case 4: gcd=v; $('skd').title=v; break; } } function getcolors(){ var colors=""; colors=ocx.GetColor(); var t= new Array(); if (colors !="") { t=colors.split(','); sldtopos(gslda,parseInt(t[0])); sldtopos(gsldb,parseInt(t[1])); sldtopos(gsldc,parseInt(t[2])); sldtopos(gsldd,parseInt(t[3])); setcolorsv(1,parseInt(t[0])); setcolorsv(2,parseInt(t[1])); setcolorsv(3,parseInt(t[2])); setcolorsv(4,parseInt(t[3])); } else//��