PT-2018-3874 · Qsee+7 · Qsee+10

Capitan_Alfa

+1

·

Published

2018-04-09

·

Updated

2025-01-18

·

CVE-2018-9995

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login
Description The issue allows remote attackers to bypass authentication via a "Cookie: uid=admin" header. This can be demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response. Exploitation of this issue may allow a remote attacker to bypass security restrictions and gain unauthorized access to protected information by sending a specially crafted request. There has been a spike in attacks against TBK DVR devices.
Recommendations For TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, consider disabling the uid=admin header in the Cookie to prevent authentication bypass until a patch is available. As a temporary workaround, restrict access to the device.rsp?opt=user&cmd=list endpoint to minimize the risk of exploitation. Avoid using the uid variable in the Cookie header in the affected devices until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02753
CVE-2018-9995

Affected Products

Cenova
Dvr Login
Hvr Login
Night Owl
Novo
Pulnix
Qsee
Securus
Tbk Dvr-4104
Tbk Dvr-4216
Xvr 5 In 1