DVRDVS-Webs
tcp/80
This vulnerability (with proof of concept (PoC) code) affects DVR/NVR devices built using the HiSilicon hi3520d and similar system on a chip (SoC).
Exploiting the vulnerabilities lead to unauthorized remote code execution (RCE) using only the web interface, causing full takeover of the exploited device
Severity: high
Fingerprint: 321975614123c6c05f83e99b0bed4eab8254eba08254eba08254eba08254eba0
Found HiSiliconDVR firmware: Hardware: General MBD6304T Vulnerable to multiple issues : LFI, possibly RCE
Open service 58.71.199.34:80
2024-10-28 19:36
HTTP/1.0 302 Redirect Server: DVRDVS-Webs Date: Mon Oct 28 22:33:18 2024 Pragma: no-cache Cache-Control: no-cache Content-Type: text/html Location: http://58.71.199.34/index.asp <html><head></head><body> This document has moved to a new <a href="http://58.71.199.34/index.asp">location</a>. Please update your documents to reflect the new location. </body></html>