PT-2024-27378 · Tbk · Tbk Dvr-4104 +1

Netsecfish

·

Published

2024-04-13

·

Updated

2025-12-10

·

CVE-2024-3721

CVSS v2.0
6.5
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TBK DVR-4104 and TBK DVR-4216 versions up to 20240412
Description A critical vulnerability exists in TBK DVR-4104 and DVR-4216 devices. This issue stems from a failure to neutralize special elements within the operating system when processing
mdb
and
mdc
parameters through the
/device.rsp?opt=sys&cmd=  S O S T R E A MAX  
endpoint. Successful exploitation allows a remote attacker to execute arbitrary commands or cause a denial of service by sending a specially crafted POST request. This vulnerability, identified as CVE-2024-3721, has been actively exploited by a new variant of the Mirai botnet, resulting in over 50,000 infected devices globally, particularly in Russia, China, Egypt, India, Brazil, and Turkey. The botnet utilizes RC4 encryption and anti-VM techniques to evade detection. The vulnerability is a command injection flaw, where manipulation of the
mdb
/
mdc
arguments leads to operating system command injection via the
/device.rsp
API endpoint.
Recommendations TBK DVR-4104 versions prior to 20240412 TBK DVR-4216 versions prior to 20240412

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-06507
CVE-2024-3721

Affected Products

Tbk Dvr-4104
Tbk Dvr-4216