PT-2025-29891 · Lilin · Lilin Digital Video Recorder
360 Netlab
·
Published
2025-07-16
·
Updated
2025-07-17
·
CVE-2025-34129
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LILIN Digital Video Recorder (DVR) versions prior to 2.0b60 20200207
Description
A command injection issue exists due to insufficient sanitization of the FTP and NTP Server fields in the service configuration. An attacker with access to the configuration interface can upload a malicious XML file with injected shell commands in these fields. Upon subsequent configuration syncs, these commands are executed with elevated privileges. This issue was exploited in the wild by the Moobot botnets.
Recommendations
Update to firmware version 2.0b60 20200207 or later.
Fix
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lilin Digital Video Recorder