PT-2024-27378 · Tbk · Tbk Dvr-4216+1
Netsecfish
·
Published
2024-04-13
·
Updated
2026-02-20
·
CVE-2024-3721
CVSS v2.0
6.5
Medium
| AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
TBK DVR-4104 and TBK DVR-4216 versions up to 20240412
Description
A critical vulnerability exists in TBK DVR-4104 and DVR-4216 devices. This issue stems from a failure to neutralize special elements within the operating system when processing
mdb and mdc parameters through the /device.rsp?opt=sys&cmd= S O S T R E A MAX endpoint. Successful exploitation allows a remote attacker to execute arbitrary commands or cause a denial of service by sending a specially crafted POST request. This vulnerability, identified as CVE-2024-3721, has been actively exploited by a new variant of the Mirai botnet, resulting in over 50,000 infected devices globally, particularly in Russia, China, Egypt, India, Brazil, and Turkey. The botnet utilizes RC4 encryption and anti-VM techniques to evade detection. The vulnerability is a command injection flaw, where manipulation of the mdb/mdc arguments leads to operating system command injection via the /device.rsp API endpoint.Recommendations
TBK DVR-4104 versions prior to 20240412
TBK DVR-4216 versions prior to 20240412
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tbk Dvr-4104
Tbk Dvr-4216