This vulnerability (with proof of concept (PoC) code) affects DVR/NVR devices built using the HiSilicon hi3520d and similar system on a chip (SoC).
Exploiting the vulnerabilities lead to unauthorized remote code execution (RCE) using only the web interface, causing full takeover of the exploited device
Severity: high
Fingerprint: 321975614123c6c05f83e99bc93924da429d31cb429d31cb429d31cb429d31cb
Found HiSiliconDVR firmware: Hardware: General TVI3208_HH Vulnerable to multiple issues : LFI, possibly RCE
Open service 183.89.234.105:8022
2024-10-28 20:38
Open service 183.89.234.105:80
2024-10-28 15:46
HTTP/1.1 200 OK Cache-control:no-cache, no-store, max-age=0 Content-Type:text/html; charset=UTF-8 Pragma:no-cache Transfer-Encoding:chunked X-Frame-Options:SAMEORIGIN Connection:Keep-Alive X-XSS-Protection:1; mode=block Content-Security-Policy:default-src 'self' 'unsafe-inline' 'unsafe-eval'