Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd.

Project Subscriptions

Vendors Products
Xiongmaitech Subscribe
Mbd6304t Subscribe
Mbd6304t Firmware Subscribe
Nbd6808t-pl Subscribe
Nbd6808t-pl Firmware Subscribe
Nbd7004t-p Subscribe
Nbd7004t-p Firmware Subscribe
Nbd7008t-p Subscribe
Nbd7008t-p Firmware Subscribe
Nbd7016t-f-v2 Subscribe
Nbd7016t-f-v2 Firmware Subscribe
Nbd7024h-p Subscribe
Nbd7024h-p Firmware Subscribe
Nbd7024t-p Subscribe
Nbd7024t-p Firmware Subscribe
Nbd7804r-f\(ep\) Subscribe
Nbd7804r-f\(ep\) Firmware Subscribe
Nbd7804r-f\(hdmi\) Subscribe
Nbd7804r-f\(hdmi\) Firmware Subscribe
Nbd7804r-fw Subscribe
Nbd7804r-fw Firmware Subscribe
Nbd7804t-pl Subscribe
Nbd7804t-pl Firmware Subscribe
Nbd7808r-pl\(ep\) Subscribe
Nbd7808r-pl\(ep\) Firmware Subscribe
Nbd7808r-pl\(hdmi\) Subscribe
Nbd7808r-pl\(hdmi\) Firmware Subscribe
Nbd7808t-pl Subscribe
Nbd7808t-pl Firmware Subscribe
Nbd7904r-fs Subscribe
Nbd7904r-fs Firmware Subscribe
Nbd7904t-p Subscribe
Nbd7904t-p Firmware Subscribe
Nbd7904t-pl Subscribe
Nbd7904t-pl-xpoe Subscribe
Nbd7904t-pl-xpoe Firmware Subscribe
Nbd7904t-pl Firmware Subscribe
Nbd7904t-plc-xpoe Subscribe
Nbd7904t-plc-xpoe Firmware Subscribe
Nbd7904t-q Subscribe
Nbd7904t-q Firmware Subscribe
Nbd7908t-q Subscribe
Nbd7908t-q Firmware Subscribe
Nbd8004r-pl\(ep\) Subscribe
Nbd8004r-pl\(ep\) Firmware Subscribe
Nbd8004r-yl\(ep\) Subscribe
Nbd8004r-yl\(ep\) Firmware Subscribe
Nbd8004t-q Subscribe
Nbd8004t-q Firmware Subscribe
Nbd8008r-pl Subscribe
Nbd8008r-pl\(ep\) Subscribe
Nbd8008r-pl\(ep\) Firmware Subscribe
Nbd8008r-pl Firmware Subscribe
Nbd8008r-yl\(ep\) Subscribe
Nbd8008r-yl\(ep\) Firmware Subscribe
Nbd8008ra-gl Subscribe
Nbd8008ra-gl Firmware Subscribe
Nbd8008ra-glk Subscribe
Nbd8008ra-glk Firmware Subscribe
Nbd8008ra-ul\(ep\) Subscribe
Nbd8008ra-ul\(ep\) Firmware Subscribe
Nbd8008ra-ula Subscribe
Nbd8008ra-ula Firmware Subscribe
Nbd8008ra-ulk Subscribe
Nbd8008ra-ulk Firmware Subscribe
Nbd8008t-q Subscribe
Nbd8008t-q Firmware Subscribe
Nbd8009s-ula-v2 Subscribe
Nbd8009s-ula-v2 Firmware Subscribe
Nbd8010s-kl-v2 Subscribe
Nbd8010s-kl-v2 Firmware Subscribe
Nbd8016r-ul Subscribe
Nbd8016r-ul Firmware Subscribe
Nbd8016ra-k\(ep\) Subscribe
Nbd8016ra-k\(ep\) Firmware Subscribe
Nbd8016ra-ul Subscribe
Nbd8016ra-ul\(ep\) Subscribe
Nbd8016ra-ul\(ep\) Firmware Subscribe
Nbd8016ra-ul Firmware Subscribe
Nbd8016ra-ula Subscribe
Nbd8016ra-ula Firmware Subscribe
Nbd8016ra-ulk Subscribe
Nbd8016ra-ulk Firmware Subscribe
Nbd8016s-kl-v2 Subscribe
Nbd8016s-kl-v2 Firmware Subscribe
Nbd8016s-ula-v2 Subscribe
Nbd8016s-ula-v2 Firmware Subscribe
Nbd8016t-q-v2 Subscribe
Nbd8016t-q-v2 Firmware Subscribe
Nbd8025r-ul Subscribe
Nbd8025r-ul Firmware Subscribe
Nbd8032h4-p Subscribe
Nbd8032h4-p Firmware Subscribe
Nbd8032h4-q Subscribe
Nbd8032h4-q Firmware Subscribe
Nbd8032h4-qe Subscribe
Nbd8032h4-qe Firmware Subscribe
Nbd8032h4-ul Subscribe
Nbd8032h4-ul Firmware Subscribe
Nbd8032h8-p Subscribe
Nbd8032h8-p Firmware Subscribe
Nbd8032h8-qe Subscribe
Nbd8032h8-qe Firmware Subscribe
Nbd8032ra-ul-v2 Subscribe
Nbd8032ra-ul-v2 Firmware Subscribe
Nbd8064h8-p Subscribe
Nbd8064h8-p Firmware Subscribe
Nbd80n16ra-kl Subscribe
Nbd80n16ra-kl\(ep\) Subscribe
Nbd80n16ra-kl\(ep\) Firmware Subscribe
Nbd80n16ra-kl Firmware Subscribe
Nbd80s08s-kl\(ep\) Subscribe
Nbd80s08s-kl\(ep\) Firmware Subscribe
Nbd80s10s-kl Subscribe
Nbd80s10s-kl Firmware Subscribe
Nbd80s16s-kl Subscribe
Nbd80s16s-kl\(ep\) Subscribe
Nbd80s16s-kl\(ep\) Firmware Subscribe
Nbd80s16s-kl Firmware Subscribe
Nbd80x09ra-kl Subscribe
Nbd80x09ra-kl Firmware Subscribe
Nbd80x09s-kl Subscribe
Nbd80x09s-kl Firmware Subscribe
Nbd88x09s-kl Subscribe
Nbd88x09s-kl Firmware Subscribe
Nbd8904r-pl Subscribe
Nbd8904r-pl Firmware Subscribe
Nbd8904r-yl Subscribe
Nbd8904r-yl Firmware Subscribe
Nbd8904t-gsc-xpoe Subscribe
Nbd8904t-gsc-xpoe Firmware Subscribe
Nbd8904t-q Subscribe
Nbd8904t-q Firmware Subscribe
Nbd8908r-pl Subscribe
Nbd8908r-pl Firmware Subscribe
Nbd8908r-yl Subscribe
Nbd8908r-yl Firmware Subscribe
Nbd8908t-pl-xpoe Subscribe
Nbd8908t-pl-xpoe Firmware Subscribe
Nbd8908t-plc-xpoe Subscribe
Nbd8908t-plc-xpoe Firmware Subscribe
Nbd8916f4-q Subscribe
Nbd8916f4-q Firmware Subscribe
Nbd8916f8-q Subscribe
Nbd8916f8-q Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-47970 Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 24 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-24T20:09:06.565Z

Reserved: 2022-11-08T00:00:00.000Z

Link: CVE-2022-45045

cve-icon Vulnrichment

Updated: 2024-08-03T14:01:31.484Z

cve-icon NVD

Status : Modified

Published: 2022-12-01T05:15:12.043

Modified: 2025-04-24T20:15:29.603

Link: CVE-2022-45045

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses