CVE 8.7 HIGH

LILIN DVR Arbitrary File Read via net_html.cgi_CVE-2025-34130

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin/net_html.cgi endpoint. This vulnerability allows attackers to read sensitive configuration files, such as /zconf/service.xml, which can then be used to facilitate further attacks including command injection. The vulnerability has been exploited in the wild in conjunction with other issues by botnets like FBot and Moobot.

Basic Information

ID CVE-2025-34130
Source VulnCheck
Published Jul 16, 2025 at 21:26
Modified Jul 17, 2025 at 13:41

Affected Product

Vendor Merit LILIN
Product DVR Firmware
Version *
Affected Versions Merit LILIN DVR Firmware *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.