CVE-2025-34129: LILIN DVR RCE via Malicious FTP/NTP Configuration
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b6020200207 due to insufficient sanitization of the FTP and NTP Server fields in the service configuration. An attacker with access to the configuration interface can upload a malicious XML file with injected shell commands in these fields. Upon subsequent configuration syncs, these commands are executed with elevated privileges. This vulnerability was exploited in the wild by the Moobot botnets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34129?
CVE-2025-34129 is classified as a critical command injection vulnerability that can allow attackers to execute arbitrary commands on affected LILIN DVR devices.
How do I fix CVE-2025-34129?
To fix CVE-2025-34129, users should upgrade their LILIN Digital Video Recorder firmware to version 2.0b60_20200207 or later.
What devices are affected by CVE-2025-34129?
CVE-2025-34129 affects all LILIN Digital Video Recorder devices running firmware versions prior to 2.0b60_20200207.
How does CVE-2025-34129 exploit work?
CVE-2025-34129 exploits insufficient sanitization of input fields, allowing an attacker to inject malicious commands through the FTP and NTP server fields in the configuration.
What are the potential impacts of CVE-2025-34129?
Exploitation of CVE-2025-34129 can lead to unauthorized command execution, potentially giving attackers access to control over the DVR and connected systems.