CVE-2025-34043: Vacron NVR Remote Command Execution
A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.cgi script. The vulnerability allows unauthenticated attackers to pass arbitrary commands to the underlying operating system via crafted HTTP requests. These commands are executed with the privileges of the web server process, enabling remote code execution and potential full device compromise. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34043?
CVE-2025-34043 has been rated as a critical vulnerability due to its potential for remote command injection.
How do I fix CVE-2025-34043?
Fixing CVE-2025-34043 involves updating the Vacron Network Video Recorder to the latest version that patches this vulnerability.
Who is affected by CVE-2025-34043?
CVE-2025-34043 affects Vacron Network Video Recorder devices running version 1.4.
What can attackers do with CVE-2025-34043?
Attackers exploiting CVE-2025-34043 can execute arbitrary commands on the underlying operating system without authentication.
How can I mitigate the risks of CVE-2025-34043?
To mitigate the risks of CVE-2025-34043, it's crucial to restrict network access to the Vacron NVR and implement strict firewall rules.