CVE Details
Basic Information
| Title | Unauthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2 |
|---|---|
| Type | cve |
| Published | 2025-07-22T20:43:18.637Z |
| Modified | 2025-07-22T20:43:18.637Z |
Product Information
| Vendor | TP-Link Systems Inc. |
|---|---|
| Product | VIGI NVR1104H-4P V1 |
| Version | 0 |
CVSS Information
| Base Score | 9.3 (CRITICAL) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Affected Products
- TP-Link Systems Inc. VIGI NVR1104H-4P V1 0
- TP-Link Systems Inc. VIGI NVR2016H-16MP V2 0
Additional Information
| CWE List | CWE-78 |
|---|---|
| Source | TPLink |
Description
An unauthenticated OS command injection vulnerability existsย in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.