CVE-2025-34132

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field in the NTPUpdate configuration. The web service at /z/zbin/dvr_box fails to properly sanitize input, allowing remote attackers to inject and execute arbitrary commands as root by supplying specially crafted XML data to the DVRPOST interface. 777
CVSS

No CVSS.

Configurations

No configuration.

History

16 Jul 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-16 22:15

Updated : 2025-07-17 21:15


NVD link : CVE-2025-34132

Mitre link : CVE-2025-34132

CVE.ORG link : CVE-2025-34132


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')