Mbd6304t
Vulnerabilities
2
Known exploited
0
Max CVSS
9.8
Top EPSS
0.05673
Severity breakdown
Critical
1
High
1
Medium
0
Low
0
Also matched as (raw): nbd8008ra-ul(ep),nbd7804r-f(hdmi),nbd7804r-fw,nbd8064h8-p,nbd88x09s-kl,nbd8016s-kl-v2,nbd7904t-q,nbd8010s-kl-v2,nbd80s10s-kl,nbd7808r-pl(hdmi),nbd8004r-yl(ep),nbd8016t-q-v2
Top vulnerabilities
CVE-2022-45460Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote user to exploit a stack-based buffer overflow and crash the web server, resulting in a system reboot. An unauthenticated and remote attacker can execute arbitrary code by sending a crafted HTTP request that triggers the overflow condition via a long URI passed to a sprintf call. NOTE: this is different than CVE-2018-10088, but this may overlap CVE-2017-16725.
CVE-2022-45045Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd.