This vulnerability (with proof of concept (PoC) code) affects DVR/NVR devices built using the HiSilicon hi3520d and similar system on a chip (SoC).
Exploiting the vulnerabilities lead to unauthorized remote code execution (RCE) using only the web interface, causing full takeover of the exploited device
Severity: high
Fingerprint: 321975614123c6c05f83e99b58badd1b26f1bcd026f1bcd026f1bcd026f1bcd0
Found HiSiliconDVR firmware: Hardware: General TVI3104_F Vulnerable to multiple issues : LFI, possibly RCE
Open service 188.136.146.59:9001
2022-11-18 14:20
Content-Type: text/html; charset=utf-8 Content-Length: 106 Connection: close Page title: 403 Forbidden <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center></body></html>