PT-2024-2534 · Hitron Systems · Hitron Systems Dvr Lguvr-4H

Published

2024-01-22

·

Updated

2025-12-31

·

CVE-2024-22771

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Hitron Systems DVR LGUVR-4H versions 1.02 through 4.02
Description The issue is related to the use of default credentials in the Hitron Systems DVR LGUVR-4H, which can be exploited by a remote attacker to cause a denial of service by utilizing the default network identifier. This can lead to a network attack when the default admin ID and password are used.
Recommendations For versions 1.02 through 4.02, change the default admin ID and password to prevent exploitation. As a temporary workaround, consider restricting access to the device until the default credentials can be changed.

Fix

Using Hardcoded Credentials

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-02519
CVE-2024-22771

Affected Products

Hitron Systems Dvr Lguvr-4H