PT-2018-3874 · Qsee+7 · Qsee+10
Capitan_Alfa
+1
·
Published
2018-04-09
·
Updated
2025-01-18
·
CVE-2018-9995
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login
Description
The issue allows remote attackers to bypass authentication via a "Cookie: uid=admin" header. This can be demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response. Exploitation of this issue may allow a remote attacker to bypass security restrictions and gain unauthorized access to protected information by sending a specially crafted request. There has been a spike in attacks against TBK DVR devices.
Recommendations
For TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, consider disabling the
uid=admin header in the Cookie to prevent authentication bypass until a patch is available.
As a temporary workaround, restrict access to the device.rsp?opt=user&cmd=list endpoint to minimize the risk of exploitation.
Avoid using the uid variable in the Cookie header in the affected devices until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Authentication
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cenova
Dvr Login
Hvr Login
Night Owl
Novo
Pulnix
Qsee
Securus
Tbk Dvr-4104
Tbk Dvr-4216
Xvr 5 In 1