This vulnerability (with proof of concept (PoC) code) affects DVR/NVR devices built using the HiSilicon hi3520d and similar system on a chip (SoC).
Exploiting the vulnerabilities lead to unauthorized remote code execution (RCE) using only the web interface, causing full takeover of the exploited device
Severity: high
Fingerprint: 321975614123c6c05f83e99bf30ea5eb22cca46022cca46022cca46022cca460
Found HiSiliconDVR firmware: Hardware: General AHB7008T-MHV2 Vulnerable to multiple issues : LFI, possibly RCE
Open service 188.136.196.57:22
2023-03-20 09:01
TCP connection dump: 00000000 53 53 48 2d 32 2e 30 2d 52 4f 53 53 53 48 0d 0a |SSH-2.0-ROSSSH..|
Open service 188.136.196.57:23
2023-03-20 00:57
Open service 188.136.196.57:23
2023-02-10 01:33
Open service 188.136.196.57:23
2023-03-03 09:14
Open service 188.136.196.57:80
2023-02-27 17:10
HTTP/1.0 200 OK Content-type: text/html Server: uc-httpd 1.0.0 Expires: 0 Page title: NETSurveillance WEB
Open service 188.136.196.57:22
2023-03-06 20:41
TCP connection dump: 00000000 53 53 48 2d 32 2e 30 2d 52 4f 53 53 53 48 0d 0a |SSH-2.0-ROSSSH..|
Open service 188.136.196.57:80
2023-03-04 16:46
HTTP/1.0 200 OK Content-type: text/html Server: uc-httpd 1.0.0 Expires: 0 Page title: NETSurveillance WEB
Open service 188.136.196.57:22
2023-03-09 18:38
TCP connection dump: 00000000 53 53 48 2d 32 2e 30 2d 52 4f 53 53 53 48 0d 0a |SSH-2.0-ROSSSH..|
Open service 188.136.196.57:22
2023-02-16 21:31
TCP connection dump: 00000000 53 53 48 2d 32 2e 30 2d 52 4f 53 53 53 48 0d 0a |SSH-2.0-ROSSSH..|
Open service 188.136.196.57:22
2023-02-15 21:33
TCP connection dump: 00000000 53 53 48 2d 32 2e 30 2d 52 4f 53 53 53 48 0d 0a |SSH-2.0-ROSSSH..|
Open service 188.136.196.57:80
2023-02-14 10:03
HTTP/1.0 200 OK Content-type: text/html Server: uc-httpd 1.0.0 Expires: 0 Page title: NETSurveillance WEB
Open service 188.136.196.57:80
2023-02-16 07:29
HTTP/1.0 200 OK Content-type: text/html Server: uc-httpd 1.0.0 Expires: 0 Page title: NETSurveillance WEB
Open service 188.136.196.57:22
2023-02-07 15:06
TCP connection dump: 00000000 53 53 48 2d 32 2e 30 2d 52 4f 53 53 53 48 0d 0a |SSH-2.0-ROSSSH..|
Open service 188.136.196.57:23
2023-03-16 17:55
Open service 188.136.196.57:23
2023-03-18 16:13