logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2018-9995

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2018-9995

Description:
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.
Last updated date:
10/03/2019

Reports

alt

ACTIVELY EXPLOITED

Type:
exploitation
Confidence:
HIGH
Date of publishing:
05/01/2023
Reference url to background

https://fortiguard.fortinet.com/outbreak-alert/tbk-dvr-attack

Type:
exploit
Confidence:
HIGH
Date of publishing:
04/29/2018
Type:
exploit
Confidence:
HIGH
Date of publishing:
05/08/2018
Type:
exploit
Confidence:
HIGH
Date of publishing:
05/09/2018
Type:
exploit
Confidence:
HIGH
Date of publishing:
06/30/2018
Reference url to background

https://github.com/shacojx/cve-2018-9995

Type:
exploit
Confidence:
HIGH
Date of publishing:
09/23/2018
Reference url to background

https://github.com/Cyb0r9/DVR-Exploiter

Type:
exploit
Confidence:
HIGH
Date of publishing:
10/03/2019
Type:
exploit
Confidence:
HIGH
Date of publishing:
10/03/2019
Type:
exploit
Confidence:
HIGH
Date of publishing:
10/03/2019
Type:
exploit
Confidence:
HIGH
Date of publishing:
10/03/2019
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/15/2020
Reference url to background

https://github.com/withmasday/HTC

Type:
exploit
Confidence:
HIGH
Date of publishing:
02/15/2020
Reference url to background

https://github.com/wmasday/HTC

Type:
exploit
Confidence:
HIGH
Date of publishing:
06/26/2020
Type:
exploit
Confidence:
HIGH
Date of publishing:
06/07/2021
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/07/2022
Type:
exploit
Confidence:
HIGH
Date of publishing:
08/18/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
09/24/2023
Reference url to background

https://github.com/Pab450/CVE-2018-9995

Type:
exploit
Confidence:
HIGH
Date of publishing:
02/18/2024
Reference url to background

https://github.com/X3RX3SSec/DVR_Sploit

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy