ZeroHour

CVE-2019-20085

KEV PoC ×2large

Unauthenticated Directory Traversal in TVT NVMS-1000 NVR Devices

CISA: TVT NVMS-1000 Directory Traversal Vulnerability

CVSS 3.1
7.5 high
EPSS
96%p100
Published
()
KEV added
AI analysis

CVE-2019-20085 is an unauthenticated directory traversal flaw (CWE-22) in the web interface of TVT NVMS-1000 network video management (NVR/VMS) software. A remote attacker with no credentials can trigger it by sending crafted GET requests containing ../ traversal sequences (e.g., GET /../), which the device resolves outside its intended web root. Successful exploitation allows arbitrary file reads from the device, potentially exposing configuration and credential files, with no integrity or availability impact (CVSS 3.1 7.5, confidentiality-only). Any deployment of TVT NVMS-1000 firmware is affected, with the greatest risk on devices whose web interface is exposed to the internet. The flaw has public PoC exploits (Packet Storm, Exploit-DB), a very high 96.1% EPSS score, and was added to the CISA KEV catalog on 2021-11-03, indicating known active exploitation.

What to do: Apply updated NVMS-1000 firmware per vendor instructions, as CISA's required action states; no specific fixed version is given in the available data, so contact TVT for the current patched release. Until patched, restrict the NVMS-1000 web interface to trusted networks via firewall/VPN rules and review HTTP access logs for GET requests containing ../ traversal patterns. Prioritize internet-exposed devices first, given the KEV listing and very high EPSS score.

Affected
TVT NVMS-1000 firmware
Estimated exposure
largeon the order of tens of thousands of internet-exposed NVMS-1000 device deployments (exact counts not in source data) — TVT NVMS-1000 is widely deployed NVR/VMS software that TVT also supplies OEM across many CCTV brands, and public internet scans have historically indexed tens of thousands of exposed NVMS-1000 instances, supporting a 10k-100k-system…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

TVT NVMS-1000 devices allow GET /.. Directory Traversal

CISA Known Exploited Vulnerability
Affected
TVT NVMS-1000
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
tvt
Products
nvms-1000 firmware
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.