ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-30162
Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field.

Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field.

NVD description · AI analysis pending
6.1<1% PoC
  • auntvt timo
CVE-2025-34036
Unauthenticated command-injection RCE in TVT white-label DVR 'Cross Web Server'

An unauthenticated OS command injection vulnerability (CWE-78) exists in the 'Cross Web Server' custom HTTP service embedded in white-labeled DVRs manufactured by TVT, which listens on TCP ports 81 and 82. When the service handles a request for /language/[lang]/index.html, it passes the [lang] portion of the URI path into a tar extraction command without sanitization or escaping, allowing an attacker to append arbitrary shell commands to the request. Because the web service runs as root, successful injection results in arbitrary command execution with full root privileges on the device. Any TVT-manufactured white-label DVR running the affected Cross Web Server software — including the listed TD-series models, which are sold under many rebrand names — is affected when the service is reachable by an attacker. Exploitation in the wild was observed by the Shadowserver Foundation on 2025-02-06 UTC, and with public exploit code documented since 2016, a maximum CVSS 4.0 score of 10.0, and a 26.9% EPSS probability of exploitation within 30 days, defenders should assume active scanning and compromise attempts.

Do: Inventory all TVT-based and white-label DVRs exposing the Cross Web Server on TCP ports 81/82, restrict access with firewall rules or VPN rather than direct internet port forwarding, and obtain patched firmware from your DVR brand/vendor (TVT OEM) as it becomes available, since no fixed version numbers are provided in the available data. Because exploitation yields root-level code execution, treat any device showing signs of compromise — requests to /language/[lang]/index.html paths, unexpected processes, or unexplained outbound connections since 2025-02-06 — as fully compromised and reflash or replace it. Continue monitoring vendor advisories and Shadowserver/CISA reporting for updated indicators of compromise and patch guidance.

10.027% PoC ×2
  • tvt td-2108ts-cl firmware
  • tvt td-2108ts-cl-a firmware
  • tvt td-2116ts-cl firmware
  • +9 more
mass≈100,000+ internet-exposed TVT-based DVRs (order-of-magnitude estimate)
CVE-2024-7339
A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problemati

A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273262 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.932% PoC
  • provision-isr sh-4050a5-5l\(mm\) firmware
  • provision-isr avision av108t firmware
  • provision-isr td-2104ts-cl firmware
  • +1 more
CVE-2024-22824
An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component.

An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component.

NVD description · AI analysis pending
9.81% PoC
  • auntvt timo
CVE-2019-20085
Unauthenticated Directory Traversal in TVT NVMS-1000 NVR Devices

CVE-2019-20085 is an unauthenticated directory traversal flaw (CWE-22) in the web interface of TVT NVMS-1000 network video management (NVR/VMS) software. A remote attacker with no credentials can trigger it by sending crafted GET requests containing ../ traversal sequences (e.g., GET /../), which the device resolves outside its intended web root. Successful exploitation allows arbitrary file reads from the device, potentially exposing configuration and credential files, with no integrity or availability impact (CVSS 3.1 7.5, confidentiality-only). Any deployment of TVT NVMS-1000 firmware is affected, with the greatest risk on devices whose web interface is exposed to the internet. The flaw has public PoC exploits (Packet Storm, Exploit-DB), a very high 96.1% EPSS score, and was added to the CISA KEV catalog on 2021-11-03, indicating known active exploitation.

Do: Apply updated NVMS-1000 firmware per vendor instructions, as CISA's required action states; no specific fixed version is given in the available data, so contact TVT for the current patched release. Until patched, restrict the NVMS-1000 web interface to trusted networks via firewall/VPN rules and review HTTP access logs for GET requests containing ../ traversal patterns. Prioritize internet-exposed devices first, given the KEV listing and very high EPSS score.

7.596% KEV PoC ×2
  • TVT NVMS-1000 firmware
largeon the order of tens of thousands of internet-exposed NVMS-1000 device deployments (exact counts not in source data)