TBK DVR Authentication Bypass Attack
ID: 3ed79378-6a51-57fe-a6c6-377777144dd6
STIX ID: report--3ed79378-6a51-57fe-a6c6-377777144dd6
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
FortiGuard Labs observed active exploitation of CVE-2018-9995 — an authentication bypass in TBK DVR devices (models 4104/4216 and many rebrands) — with tens of thousands of IPS detections in April 2023; the flaw allows remote attackers to bypass authentication and obtain administrative access to DVRs and camera feeds, and no vendor patch is known. The report also references related DVR exploits (MVPower/JAWS RCE) and FBI reporting of HiatusRAT scanning campaigns against Chinese-branded cameras and DVRs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
