CVE-2025-34043

CRITICAL EXPLOITED

Vacron NVR v1.4 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-34043 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.cgi script. The vulnerability allows unauthenticated attackers to pass arbitrary commands to the underlying operating system via crafted HTTP requests. These commands are executed with the privileges of the web server process, enabling remote code execution and potential full device compromise. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory
https://www.tenable.com/plugins/nessus/104124
Various Sources third-party-advisory signature technical-description
https://www.sonicwall.com/blog/vacron-network-video-recorder-remote-command-execution
Various Sources product
https://www.vacron.com/

Scores

CVSS v4 10.0
EPSS 0.0900
EPSS Percentile 94.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2017-10-20
CWE
CWE-20 CWE-78
Status published
Products (1)
Vacron/Network Video Recorder (NVR) 1.4
Published Jun 26, 2025
Tracked Since Feb 18, 2026