LILIN DVR Command Injection via NTPUpdate in dvr_box
Vulnerability Description
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field in the NTPUpdate configuration. The web service at /z/zbin/dvr_box fails to properly sanitize input, allowing remote attackers to inject and execute arbitrary commands as root by supplying specially crafted XML data to the DVRPOST interface.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34132
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- 360 Netlab
References
Affected Vendor
Merit LILIN
View all reports →