CVE-2024-47001

HIGH

TAKENAKA ENGINEERING CO., LTD. - Command Injection

Title source: llm
STIX 2.1

Description

Hidden functionality issue in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.

Scores

CVSS v3 8.8
EPSS 0.0086
EPSS Percentile 75.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-912
Status published
Products (9)
TAKENAKA ENGINEERING CO., LTD./AHD04T-A prior to 7xx10.1.900055.65
TAKENAKA ENGINEERING CO., LTD./AHD08T-A prior to 7xx10.1.900055.65
TAKENAKA ENGINEERING CO., LTD./AHD16T-A prior to 7xx10.1.900055.65
TAKENAKA ENGINEERING CO., LTD./HDVR-1600 prior to 53310.1.900111.65
TAKENAKA ENGINEERING CO., LTD./HDVR-400 prior to 46110.1.100869.65
TAKENAKA ENGINEERING CO., LTD./HDVR-800 prior to 53210.1.900103.65
TAKENAKA ENGINEERING CO., LTD./NVR04T-A prior to 56x10.1.100540.65
TAKENAKA ENGINEERING CO., LTD./NVR08T-A prior to 56x10.1.100540.65
TAKENAKA ENGINEERING CO., LTD./NVR16T-A prior to 49310.1.100540.65
Published Sep 18, 2024
Tracked Since Feb 18, 2026