github.comexploit
https://github.com/netsecfish/tbk_dvr_command_injection CVE-2024-3721
MEDIUM
TBK DVR-4104/DVR-4216 os command injection
Record summary
CVE-2024-3721 has a selected CVSS score of 6.3 (medium).
Description
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 21, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 2, 2024 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
DVR-4104Browse TBK / DVR-4104 | CVE List | 20240412 | affected |
DVR-4216Browse TBK / DVR-4216 | CVE List | 20240412 | affected |
TBK DVRBrowse TBK / TBK DVR | VulnCheck | Version data not supplied | |
tbk-dvr4104Browse tbkvision / tbk-dvr4104Default status: unknown | CVE List | Version range not supplied | affected |
tbk-dvr4216Browse tbkvision / tbk-dvr4216Default status: unknown | CVE List | Version range not supplied | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-3721 VDB-260573 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.260573 VDB-260573 | TBK DVR-4104/DVR-4216 os command injectionvdb entryTechnical description
https://vuldb.com/?id.260573 Submit #314969 | TBK TBK DVR-4104, TBK DVR-4216 N/A Command InjectionThird-party advisory
https://vuldb.com/?submit.314969