CVE-2018-9995

CRITICAL EXPLOITED IN THE WILD RANSOMWARE NUCLEI

TBK DVR4104/DVR4216 - Auth Bypass

Title source: llm

Description

TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.

Exploits (33)

exploitdb WORKING POC
by ezelf · pythonremotehardware
https://www.exploit-db.com/exploits/44577
nomisec WORKING POC 554 stars
by ezelf · infoleak
https://github.com/ezelf/CVE-2018-9995_dvr_credentials
nomisec WORKING POC 111 stars
by Cyb0r9 · infoleak
https://github.com/Cyb0r9/DVR-Exploiter
nomisec WORKING POC 95 stars
by 0xDamian · infoleak
https://github.com/0xDamian/CVE-2018-9995-rs
nomisec WORKING POC 11 stars
by X3RX3SSec · infoleak
https://github.com/X3RX3SSec/DVR_Sploit
nomisec WORKING POC 8 stars
by K3ysTr0K3R · infoleak
https://github.com/K3ysTr0K3R/CVE-2018-9995-EXPLOIT
nomisec WORKING POC 4 stars
by kienquoc102 · remote-auth
https://github.com/kienquoc102/CVE-2018-9995-2
nomisec SCANNER 4 stars
by zzh217 · remote-auth
https://github.com/zzh217/CVE-2018-9995_Batch_scanning_exp
nomisec WORKING POC 3 stars
by wmasday · remote
https://github.com/wmasday/HTC
nomisec WORKING POC 2 stars
by codeholic2k18 · remote
https://github.com/codeholic2k18/CVE-2018-9995
nomisec SCANNER 2 stars
by gwolfs · poc
https://github.com/gwolfs/CVE-2018-9995-ModifiedByGwolfs
nomisec SCANNER 2 stars
by Huangkey · remote
https://github.com/Huangkey/CVE-2018-9995_check
nomisec WORKING POC 1 stars
by ST0PL · infoleak
https://github.com/ST0PL/DVRFaultNET
nomisec WORKING POC 1 stars
by Saeed22487 · remote-auth
https://github.com/Saeed22487/CVE-2018-9995
nomisec WORKING POC 1 stars
by awesome-consumer-iot · poc
https://github.com/awesome-consumer-iot/HTC
nomisec WORKING POC 1 stars
by b510 · remote-auth
https://github.com/b510/CVE-2018-9995-POC
nomisec WORKING POC 1 stars
by MrAli-Code · poc
https://github.com/MrAli-Code/CVE-2018-9995_dvr_credentials
nomisec WORKING POC 1 stars
by mesutozsoycom · poc
https://github.com/mesutozsoycom/cve-2018-9995
gitlab WORKING POC
by softdream · infoleak
https://gitlab.com/softdream/CVE-2018-9995_dvr_credentials
nomisec WRITEUP
by jameseyes · poc
https://github.com/jameseyes/DVRC
nomisec WORKING POC
by its-anya · infoleak
https://github.com/its-anya/DVR_Credential_Scanner
nomisec WORKING POC
by batmoshka55 · infoleak
https://github.com/batmoshka55/CVE-2018-9995_dvr_credentials
nomisec STUB
by A-Alabdoo · infoleak
https://github.com/A-Alabdoo/CVE-DVr
nomisec WORKING POC
by dego905 · remote
https://github.com/dego905/Cam
nomisec WORKING POC
by arminarab1999 · remote
https://github.com/arminarab1999/CVE-2018-9995
nomisec WORKING POC
by LeQuocKhanh2K · remote-auth
https://github.com/LeQuocKhanh2K/Tool_Exploit_Password_Camera_CVE-2018-9995
nomisec WORKING POC
by dearpan · remote
https://github.com/dearpan/cve-2018-9995
nomisec WORKING POC
by likaifeng0 · remote-auth
https://github.com/likaifeng0/CVE-2018-9995_dvr_credentials-dev_tool
nomisec WORKING POC
by ABIZCHI · remote
https://github.com/ABIZCHI/CVE-2018-9995_dvr_credentials
nomisec WORKING POC
by TateYdq · poc
https://github.com/TateYdq/CVE-2018-9995-ModifiedByGwolfs
vulncheck_xdb WORKING POC
remote
https://github.com/threat9/routersploit

Nuclei Templates (1)

TBK DVR4104/DVR4216 Devices - Authentication Bypass
CRITICALby princechaddha

Scores

CVSS v3 9.8
EPSS 0.9412
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2020-02-25
InTheWild.io 2023-05-01
Ransomware Use Confirmed
Status published
Products (2)
tbkvision/tbk-dvr4104_firmware
tbkvision/tbk-dvr4216_firmware
Published Apr 10, 2018
Tracked Since Feb 18, 2026