CVE-2019-25240

CRITICAL

Rifatron 5brid DVR - Unauthenticated Access

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25240. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit leverages an unauthenticated stream disclosure vulnerability in Rifatron DVR devices by accessing the animate.cgi script through the Mobile Web Viewer module. It captures snapshots and renders them into a video file, demonstrating unauthorized access to live streams.

Description

Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · bashwebappscgi
https://www.exploit-db.com/exploits/47368

This exploit leverages an unauthenticated stream disclosure vulnerability in Rifatron DVR devices by accessing the animate.cgi script through the Mobile Web Viewer module. It captures snapshots and renders them into a video file, demonstrating unauthorized access to live streams.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Rifatron DVR (various models) with firmware <=8.0 (000143)
No auth needed
Prerequisites: Network access to the target device · Boa/0.94.14rc21 web server running on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Various Sources product
http://www.rifatron.com
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/47368
Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5532.php

Scores

CVSS v3 9.8
EPSS 0.0041
EPSS Percentile 32.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (3)
Rifatron Co., Ltd./DVR 5brid DVR (HD6-532/516, DX6-516/508/504, MX6-516/508/504, EH6-504)
Rifatron Co., Ltd./DVR 7brid DVR (HD3-16V2, DX3-16V2/08V2/04V2, MX3-08V2/04V2)
Rifatron Co., Ltd./DVR Firmware: <=8.0 (000143)
Published Dec 24, 2025
Tracked Since Feb 18, 2026