Unauthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2

CVE Details

Basic Information

Title Unauthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2
Type cve
Published 2025-07-22T20:43:18.637Z
Modified 2025-07-22T20:43:18.637Z

Product Information

Vendor TP-Link Systems Inc.
Product VIGI NVR1104H-4P V1
Version 0

CVSS Information

Base Score 9.3 (CRITICAL)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

  • TP-Link Systems Inc. VIGI NVR1104H-4P V1 0
  • TP-Link Systems Inc. VIGI NVR2016H-16MP V2 0

Additional Information

CWE List CWE-78
Source TPLink

Description

An unauthenticated OS command injection vulnerability existsย in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.