CVE-2018-25126: TVT NVMS-9000 Hard-coded API Credentials & Command Injection
Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and an OS command injection flaw in its configuration services. The web/API interface accepts HTTP/XML requests authenticated with a fixed vendor credential string and passes user-controlled fields into shell execution contexts without proper argument sanitization. An unauthenticated remote attacker can leverage the hard-coded credential to access endpoints such as /editBlackAndWhiteList and inject shell metacharacters inside XML parameters, resulting in arbitrary command execution as root. The same vulnerable backend is also reachable in some models through a proprietary TCP service on port 4567 that accepts a magic GUID preface and base64-encoded XML, enabling the same command injection sink. Firmware releases from mid-February 2018 and later are reported to have addressed this issue. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-28 UTC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25126?
CVE-2018-25126 is considered critical due to the presence of hardcoded API credentials and an OS command injection flaw.
How do I fix CVE-2018-25126?
To fix CVE-2018-25126, update your NVMS-9000 firmware to a version released after mid-February 2018 that addresses these vulnerabilities.
What products are affected by CVE-2018-25126?
CVE-2018-25126 affects the Shenzhen TVT Digital Technology NVMS-9000 firmware, commonly used in various DVR, NVR, and IPC products.
What are the risks associated with CVE-2018-25126?
The risks associated with CVE-2018-25126 include unauthorized access and control over the affected devices due to insecure API credentials and command injection.
Is CVE-2018-25126 publicly known?
Yes, CVE-2018-25126 is publicly known and has been documented in various security databases and advisories.