CVE-2007-6638

March Networks DVR 3204 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-6638. PoCs published by Alex Hernandez, alt3kx.

AI-analyzed exploit summary This Perl script exploits an information disclosure vulnerability in March Networks DVR 3204 by attempting to fetch log files without authentication. It checks for the presence of specific paths, including /scripts/logfiles.tar.gz, which can reveal sensitive information such as credentials and IP addresses.

Description

March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Alex Hernandez · perlremotehardware
https://www.exploit-db.com/exploits/4797

This Perl script exploits an information disclosure vulnerability in March Networks DVR 3204 by attempting to fetch log files without authentication. It checks for the presence of specific paths, including /scripts/logfiles.tar.gz, which can reveal sensitive information such as credentials and IP addresses.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: March Networks DVR 3204
No auth needed
Prerequisites: Network access to the target DVR device
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by alt3kx · poc
https://github.com/alt3kx/CVE-2007-6638

This repository references CVE-2007-6638, an information disclosure vulnerability in March Networks DVR 3204. It points to an Exploit-DB entry but contains no actual exploit code or technical details beyond a brief description.

Classification
Writeup 80%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: March Networks DVR 3204
No auth needed
Prerequisites: Network access to the vulnerable DVR device
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4797
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27054
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/39726
Various Sources x_refsource_misc
http://www.milw0rm.com/papers/190
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28211

Scores

EPSS 0.1182
EPSS Percentile 95.6%

Details

CWE
CWE-264
Status published
Products (1)
march_networks/3204_dvr
Published Jan 04, 2008
Tracked Since Feb 18, 2026