This vulnerability (with proof of concept (PoC) code) affects DVR/NVR devices built using the HiSilicon hi3520d and similar system on a chip (SoC).
Exploiting the vulnerabilities lead to unauthorized remote code execution (RCE) using only the web interface, causing full takeover of the exploited device
Severity: high
Fingerprint: 321975614123c6c05f83e99bf30ea5eb22cca46022cca46022cca46022cca460
Found HiSiliconDVR firmware: Hardware: General AHB7008T-MHV2 Vulnerable to multiple issues : LFI, possibly RCE
Open service 61.62.24.110:80
2024-09-27 21:34
HTTP/1.1 200 OK Content-type: text/html Content-Length: 1937 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Connection: close <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title></title> <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" media="screen" /> </head> <body> <div class="loadingIndicator_bk"> </div> <div class="loadingIndicator_tip"> <div style="height: 300px;"> </div> <span class="msg_border"><span class="msg"></span></span> </div> <div id="InitialView" style="background: #fff center url(css/Pictures/initview.gif) no-repeat; width: 100%; height: 100%;"></div> <div id="BaseContent"> </div> <!----> <div id="topFloatMsg"> <div id="topFloatMsg_title"> </div> <div id="topFloatMsg_body"> <div id="topFloatMsg_icon"> </div> <div id="topFloatMsg_content"> </div> </div> <div id="topFloatMsg_bottom"> </div> </div> <iframe id="topFloatMsg_bk" scrolling="no" frameborder="0" src="about:blank"></iframe> <!----> <div id="topRollMsg"> <div id="topRollMsg_title"> <span lc="html" lk="IDCS_INFO_TIP"></span> <div id="topRollMsg_close"> </div> </div> <div id="topRollMsg_content"> </div> </div> <iframe id="topRollMsg_bk" width="100%" height="100%" scrolling="no" frameborder="0" src="about:blank"></iframe> <script language="javascript" for="VideoPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> VideoPluginNotify(strXMLFormat, lStrLen); </script> <script language="javascript" for="TimeSliderPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> TimeSliderPluginNotify(strXMLFormat, lStrLen); </script> <script data-main="js/index.js?v=20221111.01" src="js/lib/require.js" type="text/javascript"></script> </body> </html>
Open service 61.62.24.110:80
2024-09-25 22:10
HTTP/1.1 200 OK Content-type: text/html Content-Length: 1937 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Connection: close <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title></title> <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" media="screen" /> </head> <body> <div class="loadingIndicator_bk"> </div> <div class="loadingIndicator_tip"> <div style="height: 300px;"> </div> <span class="msg_border"><span class="msg"></span></span> </div> <div id="InitialView" style="background: #fff center url(css/Pictures/initview.gif) no-repeat; width: 100%; height: 100%;"></div> <div id="BaseContent"> </div> <!----> <div id="topFloatMsg"> <div id="topFloatMsg_title"> </div> <div id="topFloatMsg_body"> <div id="topFloatMsg_icon"> </div> <div id="topFloatMsg_content"> </div> </div> <div id="topFloatMsg_bottom"> </div> </div> <iframe id="topFloatMsg_bk" scrolling="no" frameborder="0" src="about:blank"></iframe> <!----> <div id="topRollMsg"> <div id="topRollMsg_title"> <span lc="html" lk="IDCS_INFO_TIP"></span> <div id="topRollMsg_close"> </div> </div> <div id="topRollMsg_content"> </div> </div> <iframe id="topRollMsg_bk" width="100%" height="100%" scrolling="no" frameborder="0" src="about:blank"></iframe> <script language="javascript" for="VideoPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> VideoPluginNotify(strXMLFormat, lStrLen); </script> <script language="javascript" for="TimeSliderPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> TimeSliderPluginNotify(strXMLFormat, lStrLen); </script> <script data-main="js/index.js?v=20221111.01" src="js/lib/require.js" type="text/javascript"></script> </body> </html>
Open service 61.62.24.110:80
2024-09-15 21:49
HTTP/1.1 200 OK Content-type: text/html Content-Length: 1937 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Connection: close <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title></title> <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" media="screen" /> </head> <body> <div class="loadingIndicator_bk"> </div> <div class="loadingIndicator_tip"> <div style="height: 300px;"> </div> <span class="msg_border"><span class="msg"></span></span> </div> <div id="InitialView" style="background: #fff center url(css/Pictures/initview.gif) no-repeat; width: 100%; height: 100%;"></div> <div id="BaseContent"> </div> <!----> <div id="topFloatMsg"> <div id="topFloatMsg_title"> </div> <div id="topFloatMsg_body"> <div id="topFloatMsg_icon"> </div> <div id="topFloatMsg_content"> </div> </div> <div id="topFloatMsg_bottom"> </div> </div> <iframe id="topFloatMsg_bk" scrolling="no" frameborder="0" src="about:blank"></iframe> <!----> <div id="topRollMsg"> <div id="topRollMsg_title"> <span lc="html" lk="IDCS_INFO_TIP"></span> <div id="topRollMsg_close"> </div> </div> <div id="topRollMsg_content"> </div> </div> <iframe id="topRollMsg_bk" width="100%" height="100%" scrolling="no" frameborder="0" src="about:blank"></iframe> <script language="javascript" for="VideoPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> VideoPluginNotify(strXMLFormat, lStrLen); </script> <script language="javascript" for="TimeSliderPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> TimeSliderPluginNotify(strXMLFormat, lStrLen); </script> <script data-main="js/index.js?v=20221111.01" src="js/lib/require.js" type="text/javascript"></script> </body> </html>
Open service 61.62.24.110:80
2024-09-13 21:30
HTTP/1.1 200 OK Content-type: text/html Content-Length: 1937 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Connection: close <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title></title> <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" media="screen" /> </head> <body> <div class="loadingIndicator_bk"> </div> <div class="loadingIndicator_tip"> <div style="height: 300px;"> </div> <span class="msg_border"><span class="msg"></span></span> </div> <div id="InitialView" style="background: #fff center url(css/Pictures/initview.gif) no-repeat; width: 100%; height: 100%;"></div> <div id="BaseContent"> </div> <!----> <div id="topFloatMsg"> <div id="topFloatMsg_title"> </div> <div id="topFloatMsg_body"> <div id="topFloatMsg_icon"> </div> <div id="topFloatMsg_content"> </div> </div> <div id="topFloatMsg_bottom"> </div> </div> <iframe id="topFloatMsg_bk" scrolling="no" frameborder="0" src="about:blank"></iframe> <!----> <div id="topRollMsg"> <div id="topRollMsg_title"> <span lc="html" lk="IDCS_INFO_TIP"></span> <div id="topRollMsg_close"> </div> </div> <div id="topRollMsg_content"> </div> </div> <iframe id="topRollMsg_bk" width="100%" height="100%" scrolling="no" frameborder="0" src="about:blank"></iframe> <script language="javascript" for="VideoPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> VideoPluginNotify(strXMLFormat, lStrLen); </script> <script language="javascript" for="TimeSliderPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> TimeSliderPluginNotify(strXMLFormat, lStrLen); </script> <script data-main="js/index.js?v=20221111.01" src="js/lib/require.js" type="text/javascript"></script> </body> </html>
Open service 61.62.24.110:80
2024-09-11 22:16
HTTP/1.1 200 OK Content-type: text/html Content-Length: 1937 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Connection: close <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title></title> <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" media="screen" /> </head> <body> <div class="loadingIndicator_bk"> </div> <div class="loadingIndicator_tip"> <div style="height: 300px;"> </div> <span class="msg_border"><span class="msg"></span></span> </div> <div id="InitialView" style="background: #fff center url(css/Pictures/initview.gif) no-repeat; width: 100%; height: 100%;"></div> <div id="BaseContent"> </div> <!----> <div id="topFloatMsg"> <div id="topFloatMsg_title"> </div> <div id="topFloatMsg_body"> <div id="topFloatMsg_icon"> </div> <div id="topFloatMsg_content"> </div> </div> <div id="topFloatMsg_bottom"> </div> </div> <iframe id="topFloatMsg_bk" scrolling="no" frameborder="0" src="about:blank"></iframe> <!----> <div id="topRollMsg"> <div id="topRollMsg_title"> <span lc="html" lk="IDCS_INFO_TIP"></span> <div id="topRollMsg_close"> </div> </div> <div id="topRollMsg_content"> </div> </div> <iframe id="topRollMsg_bk" width="100%" height="100%" scrolling="no" frameborder="0" src="about:blank"></iframe> <script language="javascript" for="VideoPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> VideoPluginNotify(strXMLFormat, lStrLen); </script> <script language="javascript" for="TimeSliderPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> TimeSliderPluginNotify(strXMLFormat, lStrLen); </script> <script data-main="js/index.js?v=20221111.01" src="js/lib/require.js" type="text/javascript"></script> </body> </html>
Open service 61.62.24.110:80
2024-09-10 13:07
HTTP/1.1 200 OK Content-type: text/html Content-Length: 1937 X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Connection: close <!DOCTYPE html> <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"> <title></title> <link rel="shortcut icon" type="image/x-icon" href="/favicon.ico" media="screen" /> </head> <body> <div class="loadingIndicator_bk"> </div> <div class="loadingIndicator_tip"> <div style="height: 300px;"> </div> <span class="msg_border"><span class="msg"></span></span> </div> <div id="InitialView" style="background: #fff center url(css/Pictures/initview.gif) no-repeat; width: 100%; height: 100%;"></div> <div id="BaseContent"> </div> <!----> <div id="topFloatMsg"> <div id="topFloatMsg_title"> </div> <div id="topFloatMsg_body"> <div id="topFloatMsg_icon"> </div> <div id="topFloatMsg_content"> </div> </div> <div id="topFloatMsg_bottom"> </div> </div> <iframe id="topFloatMsg_bk" scrolling="no" frameborder="0" src="about:blank"></iframe> <!----> <div id="topRollMsg"> <div id="topRollMsg_title"> <span lc="html" lk="IDCS_INFO_TIP"></span> <div id="topRollMsg_close"> </div> </div> <div id="topRollMsg_content"> </div> </div> <iframe id="topRollMsg_bk" width="100%" height="100%" scrolling="no" frameborder="0" src="about:blank"></iframe> <script language="javascript" for="VideoPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> VideoPluginNotify(strXMLFormat, lStrLen); </script> <script language="javascript" for="TimeSliderPlugin" event="NotifyResultToJs(strXMLFormat, lStrLen)"> TimeSliderPluginNotify(strXMLFormat, lStrLen); </script> <script data-main="js/index.js?v=20221111.01" src="js/lib/require.js" type="text/javascript"></script> </body> </html>
Open service 61.62.24.110:80
2024-09-09 21:40
HTTP/1.0 200 OK Content-type: text/html Server: uc-httpd 1.0.0 Expires: 0 Page title: NETSurveillance WEB <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /> <link rel="stylesheet" type="text/css" media="screen" href="m.css" /> <title>NETSurveillance WEB</title> <!-- m.js --> <script type="text/javascript" language="JavaScript"> var ShowTipFlag=2; if(navigator.userAgent.indexOf('IE') < 0) { var userAgent = navigator.userAgent, rMsie = /(msie\s|trident.*rv:)([\w.]+)/, rFirefox = /(firefox)\/([\w.]+)/, rOpera = /(opera).+version\/([\w.]+)/, rChrome = /(chrome)\/([\w.]+)/, rSafari = /version\/([\w.]+).*(safari)/; var browserMatch = uaMatch(userAgent.toLowerCase()); if(browserMatch.browser!="IE") { location="Login.htm"; } } function reminder() { var nSel=$('langlist').selectedIndex; var cLanguage; switch(nSel) { case 0: cLanguage="English"; break; case 1: cLanguage="French"; break; case 2: cLanguage="Hungarian"; break; case 3: cLanguage="Italian"; break; case 4: cLanguage="Japanese"; break; case 5: cLanguage="Portugal"; break; case 6: cLanguage="Russian"; break; case 7: cLanguage="SimpChinese"; break; case 8: cLanguage="Spanish"; break; case 9: cLanguage="TradChinese"; break; case 10: cLanguage="German"; break; case 11: cLanguage="Poland"; break; case 12: cLanguage="Turkey"; break; case 13: cLanguage="Romanian"; break; case 14: cLanguage="Suomi"; break; case 15: cLanguage="Korean"; break; case 16: cLanguage="Farsi"; break; case 17: cLanguage="Thai"; break; case 18: cLanguage="Greek"; break; case 19: cLanguage="Vietnamese"; break; case 20: cLanguage="Brazilian"; break; case 21: cLanguage="Hebrew"; break; case 22: cLanguage="Arabic"; break; case 23: cLanguage="Bulgarian"; break; case 24: cLanguage="Czech"; break; default: cLanguage="English"; break; } if(2==ShowTipFlag) { switch(nSel) { case 0: cLanguage="English"; alert("Please set the encrypted problem!"); break; case 7: cLanguage="SimpChinese"; alert("请先设置密保问题!"); break; default: cLanguage="English"; alert("Please set the encrypted problem!"); break; } } else { location="reminder.html?cLanguage="+cLanguage; } } function uaMatch(ua) { var match = rMsie.exec(ua); if (match != null) { return { browser : "IE", version : match[2] || "0" }; } var match = rFirefox.exec(ua); if (match != null) { return { browser : match[1] || "", version : match[2] || "0" }; } var match = rOpera.exec(ua); if (match != null) {
Open service 61.62.24.110:80
2024-09-07 19:54
HTTP/1.0 200 OK Content-type: text/html Server: uc-httpd 1.0.0 Expires: 0 Page title: NETSurveillance WEB <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /> <link rel="stylesheet" type="text/css" media="screen" href="m.css" /> <title>NETSurveillance WEB</title> <!-- m.js --> <script type="text/javascript" language="JavaScript"> var ShowTipFlag=2; if(navigator.userAgent.indexOf('IE') < 0) { var userAgent = navigator.userAgent, rMsie = /(msie\s|trident.*rv:)([\w.]+)/, rFirefox = /(firefox)\/([\w.]+)/, rOpera = /(opera).+version\/([\w.]+)/, rChrome = /(chrome)\/([\w.]+)/, rSafari = /version\/([\w.]+).*(safari)/; var browserMatch = uaMatch(userAgent.toLowerCase()); if(browserMatch.browser!="IE") { location="Login.htm"; } } function reminder() { var nSel=$('langlist').selectedIndex; var cLanguage; switch(nSel) { case 0: cLanguage="English"; break; case 1: cLanguage="French"; break; case 2: cLanguage="Hungarian"; break; case 3: cLanguage="Italian"; break; case 4: cLanguage="Japanese"; break; case 5: cLanguage="Portugal"; break; case 6: cLanguage="Russian"; break; case 7: cLanguage="SimpChinese"; break; case 8: cLanguage="Spanish"; break; case 9: cLanguage="TradChinese"; break; case 10: cLanguage="German"; break; case 11: cLanguage="Poland"; break; case 12: cLanguage="Turkey"; break; case 13: cLanguage="Romanian"; break; case 14: cLanguage="Suomi"; break; case 15: cLanguage="Korean"; break; case 16: cLanguage="Farsi"; break; case 17: cLanguage="Thai"; break; case 18: cLanguage="Greek"; break; case 19: cLanguage="Vietnamese"; break; case 20: cLanguage="Brazilian"; break; case 21: cLanguage="Hebrew"; break; case 22: cLanguage="Arabic"; break; case 23: cLanguage="Bulgarian"; break; case 24: cLanguage="Czech"; break; default: cLanguage="English"; break; } if(2==ShowTipFlag) { switch(nSel) { case 0: cLanguage="English"; alert("Please set the encrypted problem!"); break; case 7: cLanguage="SimpChinese"; alert("请先设置密保问题!"); break; default: cLanguage="English"; alert("Please set the encrypted problem!"); break; } } else { location="reminder.html?cLanguage="+cLanguage; } } function uaMatch(ua) { var match = rMsie.exec(ua); if (match != null) { return { browser : "IE", version : match[2] || "0" }; } var match = rFirefox.exec(ua); if (match != null) { return { browser : match[1] || "", version : match[2] || "0" }; } var match = rOpera.exec(ua); if (match != null) {
Open service 61.62.24.110:80
2024-08-17 22:02
HTTP/1.0 200 OK Content-type: text/html Server: uc-httpd 1.0.0 Expires: 0 Page title: NETSurveillance WEB <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /> <link rel="stylesheet" type="text/css" media="screen" href="m.css" /> <title>NETSurveillance WEB</title> <!-- m.js --> <script type="text/javascript" language="JavaScript"> var ShowTipFlag=2; if(navigator.userAgent.indexOf('IE') < 0) { var userAgent = navigator.userAgent, rMsie = /(msie\s|trident.*rv:)([\w.]+)/, rFirefox = /(firefox)\/([\w.]+)/, rOpera = /(opera).+version\/([\w.]+)/, rChrome = /(chrome)\/([\w.]+)/, rSafari = /version\/([\w.]+).*(safari)/; var browserMatch = uaMatch(userAgent.toLowerCase()); if(browserMatch.browser!="IE") { location="Login.htm"; } } function reminder() { var nSel=$('langlist').selectedIndex; var cLanguage; switch(nSel) { case 0: cLanguage="English"; break; case 1: cLanguage="French"; break; case 2: cLanguage="Hungarian"; break; case 3: cLanguage="Italian"; break; case 4: cLanguage="Japanese"; break; case 5: cLanguage="Portugal"; break; case 6: cLanguage="Russian"; break; case 7: cLanguage="SimpChinese"; break; case 8: cLanguage="Spanish"; break; case 9: cLanguage="TradChinese"; break; case 10: cLanguage="German"; break; case 11: cLanguage="Poland"; break; case 12: cLanguage="Turkey"; break; case 13: cLanguage="Romanian"; break; case 14: cLanguage="Suomi"; break; case 15: cLanguage="Korean"; break; case 16: cLanguage="Farsi"; break; case 17: cLanguage="Thai"; break; case 18: cLanguage="Greek"; break; case 19: cLanguage="Vietnamese"; break; case 20: cLanguage="Brazilian"; break; case 21: cLanguage="Hebrew"; break; case 22: cLanguage="Arabic"; break; case 23: cLanguage="Bulgarian"; break; case 24: cLanguage="Czech"; break; default: cLanguage="English"; break; } if(2==ShowTipFlag) { switch(nSel) { case 0: cLanguage="English"; alert("Please set the encrypted problem!"); break; case 7: cLanguage="SimpChinese"; alert("请先设置密保问题!"); break; default: cLanguage="English"; alert("Please set the encrypted problem!"); break; } } else { location="reminder.html?cLanguage="+cLanguage; } } function uaMatch(ua) { var match = rMsie.exec(ua); if (match != null) { return { browser : "IE", version : match[2] || "0" }; } var match = rFirefox.exec(ua); if (match != null) { return { browser : match[1] || "", version : match[2] || "0" }; } var match = rOpera.exec(ua); if (match != null) {