CVE-2007-4582

ACTi Network Video Recorder SP2 2.0 - Remote Code Execution via nvUnifiedControl.AUnifiedControl.1 SetText Method

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-4582. PoCs published by shinnai.

AI-analyzed exploit summary This exploit leverages a buffer overflow vulnerability in the NVR SP2 2.0 nvUnifiedControl.AUnifiedControl.1 ActiveX control via the SetText() method, using heap spray techniques to achieve remote code execution.

Description

Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allows remote attackers to execute arbitrary code via a long second argument to the SetText method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/4322

This exploit leverages a buffer overflow vulnerability in the NVR SP2 2.0 nvUnifiedControl.AUnifiedControl.1 ActiveX control via the SetText() method, using heap spray techniques to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: NVR SP2 2.0 (nvUnifiedControl.dll v. 1.1.45.0)
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer · ActiveX control must be installed and not kill-bit set
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38441
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/36305
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4322
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25465

Scores

EPSS 0.0997
EPSS Percentile 95.0%

Details

CWE
CWE-119
Status published
Products (1)
acti/network_video_recorder sp2_2.0
Published Aug 29, 2007
Tracked Since Feb 18, 2026