Dvr Firmware
10 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Dvr Firmware, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
Dvr Firmware CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 3 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High6
Latest CVEs
The 10 most recently published vulnerabilities affecting Dvr Firmware.
- CVE-2025-34132LILIN DVR Command Injection via NTPUpdate in dvr_box—
- CVE-2025-34130LILIN DVR Arbitrary File Read via net_html.cgi—
- CVE-2025-34129LILIN DVR RCE via Malicious FTP/NTP Configuration—
- CVE-2023-28811There is a buffer overflow in the password recovery feature of Hikvision NVR/DVR models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by send...7.4
- CVE-2021-44954In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a Sudo misconfiguration.7.8
- CVE-2021-41419QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.9.8
- CVE-2020-10514iCatch DVR - Command Injection8.8
- CVE-2020-10513iCatch DVR - Broken Access Control8.8
- CVE-2013-6117Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and per...7.5
- CVE-2013-6023Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read arbitrary files via .. (dot dot) in the URI.7.8
Product grouping is registry-driven, with AI assist and human review. How it works