• News/
  • bleepingcomputer-20180502044500

New Hacking Tool Lets Users Access a Bunch of DVRs and Their Video Feeds

BleepingComputer
·
Published May 2, 2018
·
Updated

An Argentinian security researcher named Ezequiel Fernandez has published a powerful new tool yesterday that can easily extract plaintext credentials for various DVR brands and grant attackers access to those systems, and inherently the video feeds they're supposed to record. The tool, named getDVR_Credentials, is a proof-of-concept for CVE-2018-9995, a vulnerability discovered by Fernandez at the start of last month. Fernandez discovered that by accessing  the  control panel of specific DVRs with a cookie header of "Cookie: uid=admin," the DVR would respond with the device's admin credentials in cleartext. The entire exploit is small enough to fit inside a tweet.

Initially, Fernandez discovered that CVE-2018-9995 affected only DVR devices manufactured by TBK, but in an update to his original report published on Monday, the researcher expanded the list of vulnerable devices to include systems made by other vendors, most of which appeared to be selling rebranded versions of the original TBK DVR4104 and DVR4216 series. Novo CeNova QSee Pulnix XVR 5 in 1 Securus Night OWL DVR Login HVR Login MDVR Login The researcher estimated the number of vulnerable devices to at least a few tens of thousands. A screenshot of a Shodan query Fernandez used to identify vulnerable devices showed over 55,000 DVRs readily available online, while another showed 10,000 more.

Fernandez also published a few screenshots of devices he gained access to by leveraging CVE-2018-9995 and his tool. The scree...

Read full article

Affected Software

12 affected components
TBK DVR4104
TBK DVR4216
Novo DVR
CeNova DVR
QSee DVR
Pulnix DVR
XVR 5 in 1 DVR
Securus DVR
Night OWL DVR
DVR Login DVR
HVR Login DVR
MDVR Login DVR
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly released hacking tool that allows unauthorized access to various DVR systems and their video feeds.

2

Who developed the hacking tool mentioned in the article?

The hacking tool was developed by Argentinian security researcher Ezequiel Fernandez.

3

What security implications are highlighted in the article?

The article highlights that the tool can easily extract plaintext credentials, compromising security and privacy of DVR systems.

4

Which DVR brands and models are affected by the hacking tool?

Affected brands include TBK, Novo, CeNova, QSee, Pulnix, XVR 5 in 1, and Securus DVR models.

5

What is the status of the security vulnerability associated with this hacking tool?

The vulnerability is KEV-listed and was acknowledged to be exploited as of July 7, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203