PT-2024-27378 · Tbk · Tbk Dvr-4216 +1

Netsecfish

·

Published

2024-04-13

·

Updated

2025-10-21

·

CVE-2024-3721

CVSS v2.0
6.5
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TBK DVR-4104 versions up to 20240412 TBK DVR-4216 versions up to 20240412
Description A critical issue affects the processing of the file
/device.rsp?opt=sys&cmd=  S O S T R E A MAX  
. The manipulation of the argument
mdb/mdc
leads to os command injection. The attack may be initiated remotely.
Recommendations For TBK DVR-4104 versions up to 20240412, consider restricting access to the
/device.rsp
endpoint until a patch is available. For TBK DVR-4216 versions up to 20240412, consider restricting access to the
/device.rsp
endpoint until a patch is available. As a temporary workaround, avoid using the
mdb/mdc
argument in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-06507
CVE-2024-3721

Affected Products

Tbk Dvr-4104
Tbk Dvr-4216