Main
Vulnerability Database
Exploits
ID:8719 - Exploit for Improper authentication in TBK DVR4104 and TBK DVR4216 - CVE-2018-9995
ID:8719 - Exploit for Improper authentication in TBK DVR4104 and TBK DVR4216 - CVE-2018-9995
Published: January 9, 2023
Vulnerability identifier: #VU12890
Vulnerability risk: Low
CVE-ID: CVE-2018-9995
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
TBK DVR4104
TBK DVR4216
TBK DVR4104
TBK DVR4216
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to improper authentication. A remote attacker can bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.
The weakness exists due to improper authentication. A remote attacker can bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.
Remediation
Install update from vendor's website.