Description
A critical vulnerability exists in TBK DVR-4104 and DVR-4216 devices. This issue stems from a failure to neutralize special elements within the operating system when processing
mdb
and
mdc
parameters through the
/device.rsp?opt=sys&cmd= S O S T R E A MAX
endpoint. Successful exploitation allows a remote attacker to execute arbitrary commands or cause a denial of service by sending a specially crafted POST request. This vulnerability, identified as CVE-2024-3721, has been actively exploited by a new variant of the Mirai botnet, resulting in over 50,000 infected devices globally, particularly in Russia, China, Egypt, India, Brazil, and Turkey. The botnet utilizes RC4 encryption and anti-VM techniques to evade detection. The vulnerability is a command injection flaw, where manipulation of the
mdb
/
mdc
arguments leads to operating system command injection via the
/device.rsp
API endpoint.