CVE-2025-34130: LILIN DVR Arbitrary File Read via net_html.cgi
An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b6020200207 via the /z/zbin/nethtml.cgi endpoint. This vulnerability allows attackers to read sensitive configuration files, such as /zconf/service.xml, which can then be used to facilitate further attacks including command injection. The vulnerability has been exploited in the wild in conjunction with other issues by botnets like FBot and Moobot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34130?
CVE-2025-34130 has a high severity due to its potential for unauthorized access to sensitive configuration files.
How do I fix CVE-2025-34130?
To fix CVE-2025-34130, update the LILIN Digital Video Recorder to firmware version 2.0b60_20200207 or later.
What type of attack does CVE-2025-34130 enable?
CVE-2025-34130 enables unauthenticated attackers to perform arbitrary file reads on vulnerable devices.
Which devices are affected by CVE-2025-34130?
CVE-2025-34130 affects all LILIN Digital Video Recorder devices running firmware versions prior to 2.0b60_20200207.
What information can be accessed through CVE-2025-34130?
Through CVE-2025-34130, attackers can read sensitive configuration files such as /zconf/service.xml.