CVE-2024-43778

EUVD-2024-40446
OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter the device settings.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
takenaka_engineeringhdvr-400_firmware
𝑥
< 46110.1.100869.65
ADP
takenaka_engineeringhdvr-800_firmware
𝑥
< 53210.1.900103.65
ADP
takenaka_engineeringhdvr-1600_firmware
𝑥
< 53310.1.900111.65
ADP
takenaka_engineeringahd04t-a_firmware
𝑥
< 7xx10.1.900055.65
ADP
takenaka_engineeringahd08t-a_firmware
𝑥
< 7xx10.1.900055.65
ADP
takenaka_engineeringahd16t-a_firmware
𝑥
< 7xx10.1.900055.65
ADP
takenaka_engineeringnvr04t-a_firmware
𝑥
< 56x10.1.100540.65
ADP
takenaka_engineeringnvr08t-a_firmware
𝑥
< 56x10.1.100540.65
ADP
takenaka_engineeringnvr16t-a_firmware
𝑥
< 49310.1.100540.65
ADP