CVE-2019-20085
KEV PoC ×2largeUnauthenticated Directory Traversal in TVT NVMS-1000 NVR Devices
CISA: TVT NVMS-1000 Directory Traversal Vulnerability
CVE-2019-20085 is an unauthenticated directory traversal flaw (CWE-22) in the web interface of TVT NVMS-1000 network video management (NVR/VMS) software. A remote attacker with no credentials can trigger it by sending crafted GET requests containing ../ traversal sequences (e.g., GET /../), which the device resolves outside its intended web root. Successful exploitation allows arbitrary file reads from the device, potentially exposing configuration and credential files, with no integrity or availability impact (CVSS 3.1 7.5, confidentiality-only). Any deployment of TVT NVMS-1000 firmware is affected, with the greatest risk on devices whose web interface is exposed to the internet. The flaw has public PoC exploits (Packet Storm, Exploit-DB), a very high 96.1% EPSS score, and was added to the CISA KEV catalog on 2021-11-03, indicating known active exploitation.
What to do: Apply updated NVMS-1000 firmware per vendor instructions, as CISA's required action states; no specific fixed version is given in the available data, so contact TVT for the current patched release. Until patched, restrict the NVMS-1000 web interface to trusted networks via firewall/VPN rules and review HTTP access logs for GET requests containing ../ traversal patterns. Prioritize internet-exposed devices first, given the KEV listing and very high EPSS score.
| TVT NVMS-1000 firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
TVT NVMS-1000 devices allow GET /.. Directory Traversal
- Affected
- TVT NVMS-1000
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- tvt
- Products
- nvms-1000 firmware
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.