vendor:
DVR/NVR
by:
Snawoot
7.5
CVSS
HIGH
Remote Backdoor Account
CWE
Product Name: DVR/NVR
Affected Version From: hi3520d
Affected Version To: hi3520d
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2020
HiSilicon DVR/NVR hi3520d firmware – Remote Backdoor Account
This exploit targets the HiSilicon DVR/NVR hi3520d firmware and allows for remote access to a backdoor account. The exploit code provided in the POC section can be used to exploit this vulnerability.
Mitigation:
Apply the vendor patch or firmware update to fix the backdoor account vulnerability. Alternatively, restrict network access to the affected device.