CVE-2024-22514

HIGH

iSpyConnect.com Agent DVR <5.1.6.0 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-22514. PoCs published by Orange-418.

AI-analyzed exploit summary The repository describes a remote code execution vulnerability in Agent DVR 5.1.6.0, where the EXE param path in the objects.xml backup file can be modified to trigger arbitrary file execution. It mentions chaining with an arbitrary file upload vulnerability for full exploitation.

Description

An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.

Exploits (1)

nomisec WRITEUP
by Orange-418 · poc
https://github.com/Orange-418/CVE-2024-22514-Remote-Code-Execution

The repository describes a remote code execution vulnerability in Agent DVR 5.1.6.0, where the EXE param path in the objects.xml backup file can be modified to trigger arbitrary file execution. It mentions chaining with an arbitrary file upload vulnerability for full exploitation.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Agent DVR 5.1.6.0
Auth required
Prerequisites: Authenticated access to the Agent DVR dashboard · Ability to modify and restore objects.xml backup file
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0140
EPSS Percentile 69.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22 CWE-94
Status published
Products (1)
ispyconnect/agent_dvr 5.1.6.0
Published Feb 06, 2024
Tracked Since Feb 18, 2026