PT-2025-37300 · Digiever · Digiever Nvr

An-Wei Kung

+5

·

Published

2025-09-11

·

Updated

2025-09-17

·

CVE-2025-10265

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Digiever NVR (affected versions not specified)
Description Certain models of NVR developed by Digiever have an OS Command Injection vulnerability. This allows remote attackers to inject arbitrary OS commands and execute them on the device. Some reports indicate the vulnerability may be exploitable by unauthenticated attackers, while others state it requires authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-15906
CVE-2025-10265

Affected Products

Digiever Nvr