CVE-2013-6023

EXPLOITED

TVT DVR Firmware < 3.2.0.p-3520a-03 - Path Traversal via URI

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-6023 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Cesar Neira.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in TVT TD-2308SS-B DVR devices, allowing unauthorized access to sensitive configuration files via a crafted HTTP request. The PoC uses curl to retrieve the config.dat file by traversing directories.

Description

Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read arbitrary files via .. (dot dot) in the URI.

Exploits (1)

exploitdb WORKING POC
by Cesar Neira · textwebappshardware
https://www.exploit-db.com/exploits/29959

This exploit demonstrates a directory traversal vulnerability in TVT TD-2308SS-B DVR devices, allowing unauthorized access to sensitive configuration files via a crafted HTTP request. The PoC uses curl to retrieve the config.dat file by traversing directories.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: TVT TD-2308SS-B DVR (multiple firmware versions)
No auth needed
Prerequisites: Network access to the vulnerable DVR device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/785838
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/29959
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/63360

Scores

EPSS 0.2278
EPSS Percentile 96.0%

Details

VulnCheck KEV 2020-12-01
CWE
CWE-22
Status published
Products (18)
tvt/dvr td-2308ss-b
tvt/dvr_firmware 3.1.6.p-1.0.2.1-03
tvt/dvr_firmware 3.1.7.b-1.0.2.1-00
tvt/dvr_firmware 3.1.43.b
tvt/dvr_firmware 3.1.43.p
tvt/dvr_firmware 3.1.75.b-1.0.2.1-00
tvt/dvr_firmware 3.1.81.b-1.0.2.1-00
tvt/dvr_firmware 3.1.83.b-1.0.2.1-00
tvt/dvr_firmware 3.1.83.p-1.0.4.2-03
tvt/dvr_firmware 3.1.87.p-1.0.4.2-17
... and 8 more
Published Nov 02, 2013
Tracked Since Feb 18, 2026