EIP-2026-101570

PRE-CVE

Bosch Security Systems DVR 630/650/670 Series - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101570. PoCs published by dun.

AI-analyzed exploit summary This exploit demonstrates command injection vulnerabilities in Bosch Security Systems DVR 630/650/670 Series devices. It includes two methods to gain root shell access via command injection in the `DYNDNS_PWD` field and `ntp.cgi` endpoint, as well as a method to disclose admin passwords.

Description

Bosch Security Systems DVR 630/650/670 Series - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by dun · textwebappshardware
https://www.exploit-db.com/exploits/34956

This exploit demonstrates command injection vulnerabilities in Bosch Security Systems DVR 630/650/670 Series devices. It includes two methods to gain root shell access via command injection in the `DYNDNS_PWD` field and `ntp.cgi` endpoint, as well as a method to disclose admin passwords.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Bosch Security Systems DVR 630/650/670 Series
No auth needed
Prerequisites: Network access to the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026