CVE-2022-45045
01.12.2022, 05:15
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd.
Vendor | Product | Version |
---|---|---|
xiongmaitech | mbd6304t | - |
xiongmaitech | nbd6808t-pl | - |
xiongmaitech | nbd7004t-p | * |
xiongmaitech | nbd7008t-p | * |
xiongmaitech | nbd7016t-f-v2 | * |
xiongmaitech | nbd7024h-p | * |
xiongmaitech | nbd7024t-p | * |
xiongmaitech | nbd7804r-f\(ep\) | * |
xiongmaitech | nbd7804r-f\(hdmi\) | * |
xiongmaitech | nbd7804r-fw | * |
xiongmaitech | nbd7804t-pl | * |
xiongmaitech | nbd7808r-pl\(ep\) | * |
xiongmaitech | nbd7808r-pl\(hdmi\) | * |
xiongmaitech | nbd7808t-pl | * |
xiongmaitech | nbd7904r-fs | * |
xiongmaitech | nbd7904t-p | * |
xiongmaitech | nbd7904t-pl | * |
xiongmaitech | nbd7904t-pl-xpoe | - |
xiongmaitech | nbd7904t-plc-xpoe | - |
xiongmaitech | nbd7904t-q | * |
xiongmaitech | nbd7908t-q | * |
xiongmaitech | nbd8004r-pl\(ep\) | * |
xiongmaitech | nbd8004r-yl\(ep\) | - |
xiongmaitech | nbd8004t-q | * |
xiongmaitech | nbd8008r-pl | * |
xiongmaitech | nbd8008r-pl\(ep\) | * |
xiongmaitech | nbd8008r-yl\(ep\) | - |
xiongmaitech | nbd8008ra-gl | - |
xiongmaitech | nbd8008ra-glk | - |
xiongmaitech | nbd8008ra-ul\(ep\) | - |
xiongmaitech | nbd8008ra-ula | - |
xiongmaitech | nbd8008ra-ulk | - |
xiongmaitech | nbd8008t-q | * |
xiongmaitech | nbd8009s-ula-v2 | - |
xiongmaitech | nbd8010s-kl-v2 | - |
xiongmaitech | nbd8016r-ul | * |
xiongmaitech | nbd8016ra-k\(ep\) | - |
xiongmaitech | nbd8016ra-ul | - |
xiongmaitech | nbd8016ra-ul\(ep\) | - |
xiongmaitech | nbd8016ra-ula | - |
xiongmaitech | nbd8016ra-ulk | - |
xiongmaitech | nbd8016s-kl-v2 | - |
xiongmaitech | nbd8016s-ula-v2 | - |
xiongmaitech | nbd8016t-q-v2 | * |
xiongmaitech | nbd8025r-ul | * |
xiongmaitech | nbd8032h4-p | * |
xiongmaitech | nbd8032h4-q | * |
xiongmaitech | nbd8032h4-qe | * |
xiongmaitech | nbd8032h4-ul | - |
xiongmaitech | nbd8032h8-p | * |
xiongmaitech | nbd8032h8-qe | * |
xiongmaitech | nbd8032ra-ul-v2 | - |
xiongmaitech | nbd8064h8-p | * |
xiongmaitech | nbd80n16ra-kl | - |
xiongmaitech | nbd80n16ra-kl\(ep\) | - |
xiongmaitech | nbd80s08s-kl\(ep\) | - |
xiongmaitech | nbd80s10s-kl | - |
xiongmaitech | nbd80s16s-kl | - |
xiongmaitech | nbd80s16s-kl\(ep\) | - |
xiongmaitech | nbd80x09ra-kl | - |
xiongmaitech | nbd80x09s-kl | - |
xiongmaitech | nbd88x09s-kl | - |
xiongmaitech | nbd8904r-pl | * |
xiongmaitech | nbd8904r-yl | - |
xiongmaitech | nbd8904t-gsc-xpoe | - |
xiongmaitech | nbd8904t-q | * |
xiongmaitech | nbd8908r-pl | * |
xiongmaitech | nbd8908r-yl | * |
xiongmaitech | nbd8908t-pl-xpoe | - |
xiongmaitech | nbd8908t-plc-xpoe | - |
xiongmaitech | nbd8916f4-q | * |
xiongmaitech | nbd8916f8-q | * |
xiongmaitech | mbd6304t_firmware | 4.02.r11.00000117.10001.131900.00000:r11.00000117 |
xiongmaitech | nbd6808t-pl_firmware | 4.02.r11.c7431119.12001.130000.00000:r11.c7431119 |
xiongmaitech | nbd7004t-p_firmware | - |
xiongmaitech | nbd7008t-p_firmware | - |
xiongmaitech | nbd7016t-f-v2_firmware | - |
xiongmaitech | nbd7024h-p_firmware | - |
xiongmaitech | nbd7024t-p_firmware | - |
xiongmaitech | nbd7804r-f\(ep\)_firmware | - |
xiongmaitech | nbd7804r-f\(hdmi\)_firmware | - |
xiongmaitech | nbd7804r-fw_firmware | - |
xiongmaitech | nbd7804t-pl_firmware | - |
xiongmaitech | nbd7808r-pl\(ep\)_firmware | - |
xiongmaitech | nbd7808r-pl\(hdmi\)_firmware | - |
xiongmaitech | nbd7808t-pl_firmware | - |
xiongmaitech | nbd7904r-fs_firmware | - |
xiongmaitech | nbd7904t-p_firmware | - |
xiongmaitech | nbd7904t-pl_firmware | - |
xiongmaitech | nbd7904t-pl-xpoe_firmware | - |
xiongmaitech | nbd7904t-plc-xpoe_firmware | - |
xiongmaitech | nbd7904t-q_firmware | - |
xiongmaitech | nbd7908t-q_firmware | - |
xiongmaitech | nbd8004r-pl\(ep\)_firmware | - |
xiongmaitech | nbd8004r-yl\(ep\)_firmware | - |
xiongmaitech | nbd8004t-q_firmware | - |
xiongmaitech | nbd8008r-pl_firmware | - |
xiongmaitech | nbd8008r-pl\(ep\)_firmware | - |
xiongmaitech | nbd8008r-yl\(ep\)_firmware | - |
xiongmaitech | nbd8008ra-gl_firmware | - |
xiongmaitech | nbd8008ra-glk_firmware | - |
xiongmaitech | nbd8008ra-ul\(ep\)_firmware | - |
xiongmaitech | nbd8008ra-ula_firmware | - |
xiongmaitech | nbd8008ra-ulk_firmware | - |
xiongmaitech | nbd8008t-q_firmware | - |
xiongmaitech | nbd8009s-ula-v2_firmware | - |
xiongmaitech | nbd8010s-kl-v2_firmware | - |
xiongmaitech | nbd8016r-ul_firmware | - |
xiongmaitech | nbd8016ra-k\(ep\)_firmware | - |
xiongmaitech | nbd8016ra-ul_firmware | - |
xiongmaitech | nbd8016ra-ul\(ep\)_firmware | - |
xiongmaitech | nbd8016ra-ula_firmware | - |
xiongmaitech | nbd8016ra-ulk_firmware | - |
xiongmaitech | nbd8016s-kl-v2_firmware | - |
xiongmaitech | nbd8016s-ula-v2_firmware | - |
xiongmaitech | nbd8016t-q-v2_firmware | - |
xiongmaitech | nbd8025r-ul_firmware | - |
xiongmaitech | nbd8032h4-p_firmware | - |
xiongmaitech | nbd8032h4-q_firmware | - |
xiongmaitech | nbd8032h4-qe_firmware | - |
xiongmaitech | nbd8032h4-ul_firmware | - |
xiongmaitech | nbd8032h8-p_firmware | - |
xiongmaitech | nbd8032h8-qe_firmware | - |
xiongmaitech | nbd8032ra-ul-v2_firmware | - |
xiongmaitech | nbd8064h8-p_firmware | - |
xiongmaitech | nbd80n16ra-kl_firmware | - |
xiongmaitech | nbd80n16ra-kl\(ep\)_firmware | - |
xiongmaitech | nbd80s08s-kl\(ep\)_firmware | - |
xiongmaitech | nbd80s10s-kl_firmware | - |
xiongmaitech | nbd80s16s-kl_firmware | - |
xiongmaitech | nbd80s16s-kl\(ep\)_firmware | - |
xiongmaitech | nbd80x09ra-kl_firmware | - |
xiongmaitech | nbd80x09s-kl_firmware | - |
xiongmaitech | nbd88x09s-kl_firmware | - |
xiongmaitech | nbd8904r-pl_firmware | - |
xiongmaitech | nbd8904r-yl_firmware | - |
xiongmaitech | nbd8904t-gsc-xpoe_firmware | - |
xiongmaitech | nbd8904t-q_firmware | - |
xiongmaitech | nbd8908r-pl_firmware | - |
xiongmaitech | nbd8908r-yl_firmware | - |
xiongmaitech | nbd8908t-pl-xpoe_firmware | - |
xiongmaitech | nbd8908t-plc-xpoe_firmware | - |
xiongmaitech | nbd8916f4-q_firmware | - |
xiongmaitech | nbd8916f8-q_firmware | - |
𝑥
= Vulnerable software versions