blog.netlab.360.comThird-party advisoryTechnical description
https://blog.netlab.360.com/multiple-botnets-are-spreading-using-lilin-dvr-0-day CVE-2025-34129
HIGH
LILIN DVR RCE via Malicious FTP/NTP Configuration
Record summary
CVE-2025-34129 has a selected CVSS score of 8.7 (high).
Description
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 due to insufficient sanitization of the FTP and NTP Server fields in the service configuration. An attacker with access to the configuration interface can upload a malicious XML file with injected shell commands in these fields. Upon subsequent configuration syncs, these commands are executed with elevated privileges. This vulnerability was exploited in the wild by the Moobot botnets.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 20, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 17, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Digital Video Recorder (DVR)Browse LILIN / Digital Video Recorder (DVR) | VulnCheck | Version data not supplied | |
DVR FirmwareBrowse Merit LILIN / DVR FirmwareDefault status: unaffected | CVE List | Before 2.0b60_20200207 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-34129 meritlilin.comVendor advisorypatch
https://www.meritlilin.com/assets/uploads/support/file/M00158-TW.pdf vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/lilin-dvr-multiple-vulnerabilities