• News/
  • https://www.bleepingcomputer.com/news/security/new-hacking-tool-lets-users-access-a-bunch-of-dvrs-and-their-video-feeds/

New Hacking Tool Lets Users Access a Bunch of DVRs and Their Video Feeds

BleepingComputer
·
Published May 2, 2018
·
Updated

An Argentinian security researcher named Ezequiel Fernandez has published a powerful new tool yesterday that can easily extract plaintext credentials for various DVR brands and grant attackers access to those systems, and inherently the video feeds they're supposed to record. The tool, named getDVR_Credentials, is a proof-of-concept for CVE-2018-9995, a vulnerability discovered by Fernandez at the start of last month. Fernandez discovered that by accessing  the  control panel of specific DVRs with a cookie header of "Cookie: uid=admin," the DVR would respond with the device's admin credentials in cleartext. The entire exploit is small enough to fit inside a tweet.

Initially, Fernandez discovered that CVE-2018-9995 affected only DVR devices manufactured by TBK, but in an update to his original report published on Monday, the researcher expanded the list of vulnerable devices to include systems made by other vendors, most of which appeared to be selling rebranded versions of the original TBK DVR4104 and DVR4216 series. Novo CeNova QSee Pulnix XVR 5 in 1 Securus Night OWL DVR Login HVR Login MDVR Login The researcher estimated the number of vulnerable devices to at least a few tens of thousands. A screenshot of a Shodan query Fernandez used to identify vulnerable devices showed over 55,000 DVRs readily available online, while another showed 10,000 more.

Fernandez also published a few screenshots of devices he gained access to by leveraging CVE-2018-9995 and his tool. The scree...

Read full article

Affected Software

12 affected components
TBK DVR4104>=1.0
TBK DVR4216>=1.0
Novo DVR>=1.0
CeNova DVR>=1.0
QSee DVR>=1.0
Pulnix DVR>=1.0
XVR 5 in 1 DVR>=1.0
Securus DVR>=1.0
Night OWL DVR>=1.0
DVR Login DVR>=1.0
HVR Login DVR>=1.0
MDVR Login DVR>=1.0
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new hacking tool released by an Argentinian security researcher that allows attackers to access various DVRs and their video feeds.

2

What security implications are discussed in the article?

The tool can extract plaintext credentials from numerous DVR models, potentially exposing users to unauthorized access and surveillance.

3

What DVR brands and models are affected by this vulnerability?

Affected DVR brands include TBK, Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, and multiple DVR Login models.

4

Who developed this hacking tool and when was it released?

The hacking tool was developed by security researcher Ezequiel Fernandez and was published recently.

5

What version of the DVRs is primarily impacted by this tool?

The tool affects DVR models running version 1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203