PT-2025-29891 · Lilin · Lilin Digital Video Recorder

360 Netlab

·

Published

2025-07-16

·

Updated

2025-07-17

·

CVE-2025-34129

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LILIN Digital Video Recorder (DVR) versions prior to 2.0b60 20200207
Description A command injection issue exists due to insufficient sanitization of the FTP and NTP Server fields in the service configuration. An attacker with access to the configuration interface can upload a malicious XML file with injected shell commands in these fields. Upon subsequent configuration syncs, these commands are executed with elevated privileges. This issue was exploited in the wild by the Moobot botnets.
Recommendations Update to firmware version 2.0b60 20200207 or later.

Fix

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-34129

Affected Products

Lilin Digital Video Recorder