CVE-2025-34132: LILIN DVR Command Injection via NTPUpdate in dvr_box
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b6020200207 via the Server field in the NTPUpdate configuration. The web service at /z/zbin/dvrbox fails to properly sanitize input, allowing remote attackers to inject and execute arbitrary commands as root by supplying specially crafted XML data to the DVRPOST interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34132?
CVE-2025-34132 is rated as a high severity command injection vulnerability affecting LILIN Digital Video Recorder devices.
How do I fix CVE-2025-34132?
To mitigate CVE-2025-34132, update the firmware of your LILIN Digital Video Recorder to version 2.0b60_20200207 or later.
What type of vulnerability is CVE-2025-34132?
CVE-2025-34132 is classified as a command injection vulnerability.
Which devices are affected by CVE-2025-34132?
CVE-2025-34132 affects LILIN Digital Video Recorder devices running firmware prior to version 2.0b60_20200207.
How can attackers exploit CVE-2025-34132?
Attackers can exploit CVE-2025-34132 by sending crafted input through the Server field in the NTPUpdate configuration to execute arbitrary commands.