uc-httpd 1.0.0
tcp/80
This vulnerability (with proof of concept (PoC) code) affects DVR/NVR devices built using the HiSilicon hi3520d and similar system on a chip (SoC).
Exploiting the vulnerabilities lead to unauthorized remote code execution (RCE) using only the web interface, causing full takeover of the exploited device
Severity: high
Fingerprint: 321975614123c6c05f83e99be5292c1e07e8141f07e8141f07e8141f07e8141f
Found HiSiliconDVR firmware: Hardware: General DVR_P02V100R001C09 Vulnerable to multiple issues : LFI, possibly RCE
Open service 2.58.92.117:80
2024-12-22 00:58
HTTP/1.0 200 OK Content-type: application/octet-stream Server: uc-httpd/1.0.0 Content-Length: 66 Cache-Control: max-age=864000 Connection: Close <H1>Index of /mnt/web/</H1> <p><a href="//mnt/web/..">..</a></p>
Open service 2.58.92.117:80
2024-12-20 00:31
HTTP/1.0 200 OK Content-type: application/octet-stream Server: uc-httpd/1.0.0 Content-Length: 66 Cache-Control: max-age=864000 Connection: Close <H1>Index of /mnt/web/</H1> <p><a href="//mnt/web/..">..</a></p>
Open service 2.58.92.117:80
2024-12-18 01:40
HTTP/1.0 200 OK Content-type: application/octet-stream Server: uc-httpd/1.0.0 Content-Length: 66 Cache-Control: max-age=864000 Connection: Close <H1>Index of /mnt/web/</H1> <p><a href="//mnt/web/..">..</a></p>
Open service 2.58.92.117:80
2024-12-15 23:19
HTTP/1.0 200 OK Content-type: application/octet-stream Server: uc-httpd/1.0.0 Content-Length: 66 Cache-Control: max-age=864000 Connection: Close <H1>Index of /mnt/web/</H1> <p><a href="//mnt/web/..">..</a></p>
Open service 2.58.92.117:80
2024-12-13 23:00
HTTP/1.0 200 OK Content-type: application/octet-stream Server: uc-httpd/1.0.0 Content-Length: 66 Cache-Control: max-age=864000 Connection: Close <H1>Index of /mnt/web/</H1> <p><a href="//mnt/web/..">..</a></p>
Open service 2.58.92.117:80
2024-12-11 23:19
HTTP/1.0 200 OK Content-type: application/octet-stream Server: uc-httpd/1.0.0 Content-Length: 66 Cache-Control: max-age=864000 Connection: Close <H1>Index of /mnt/web/</H1> <p><a href="//mnt/web/..">..</a></p>
Open service 2.58.92.117:80
2024-12-01 23:24
HTTP/1.0 200 OK Content-type: application/octet-stream Server: uc-httpd/1.0.0 Content-Length: 66 Cache-Control: max-age=864000 Connection: Close <H1>Index of /mnt/web/</H1> <p><a href="//mnt/web/..">..</a></p>
Open service 2.58.92.117:80
2024-11-29 23:23
HTTP/1.0 200 OK Content-type: application/octet-stream Server: uc-httpd/1.0.0 Content-Length: 66 Cache-Control: max-age=864000 Connection: Close <H1>Index of /mnt/web/</H1> <p><a href="//mnt/web/..">..</a></p>
Open service 2.58.92.117:80
2024-11-28 00:03
HTTP/1.0 200 OK Content-type: application/octet-stream Server: uc-httpd/1.0.0 Content-Length: 66 Cache-Control: max-age=864000 Connection: Close <H1>Index of /mnt/web/</H1> <p><a href="//mnt/web/..">..</a></p>