This vulnerability (with proof of concept (PoC) code) affects DVR/NVR devices built using the HiSilicon hi3520d and similar system on a chip (SoC).
Exploiting the vulnerabilities lead to unauthorized remote code execution (RCE) using only the web interface, causing full takeover of the exploited device
Severity: high
Fingerprint: 321975614123c6c05f83e99bf30ea5eb22cca46022cca46022cca46022cca460
Found HiSiliconDVR firmware: Hardware: General AHB7008T-MHV2 Vulnerable to multiple issues : LFI, possibly RCE
Open service 188.136.144.37:9001
2023-01-13 18:00
Connection: close Content-Length: 7065 Content-Type: text/html Date: Fri, 13 Jan 2023 18:00:48 GMT Expires: 0 Page title: RouterOS router configuration page
Open service 188.136.144.37:9001
2023-01-08 03:19
Connection: close Content-Length: 7065 Content-Type: text/html Date: Sun, 08 Jan 2023 03:19:26 GMT Expires: 0 Page title: RouterOS router configuration page
Open service 188.136.144.37:9001
2022-12-14 12:58
Connection: close Content-Length: 7065 Content-Type: text/html Date: Wed, 14 Dec 2022 12:58:18 GMT Expires: 0 Page title: RouterOS router configuration page