CVE-2026-0854: Merit LILIN|NVR - OS Command Injection
Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0854?
CVE-2026-0854 is classified as a high severity OS Command Injection vulnerability.
How do I fix CVE-2026-0854?
To mitigate CVE-2026-0854, ensure that the affected Merit LILIN NVR devices are updated to the latest firmware that addresses this vulnerability.
What are the risks associated with CVE-2026-0854?
The risks include unauthorized access, data manipulation, and full control over the affected devices by remote attackers.
Who is affected by CVE-2026-0854?
CVE-2026-0854 affects certain models of Merit LILIN DVR/NVR devices that are vulnerable to OS Command Injection.
Is CVE-2026-0854 an authenticated vulnerability?
Yes, CVE-2026-0854 requires authentication, allowing remote attackers with access to exploit the OS Command Injection.