Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Xiongmaitech
Subscribe
|
Mbd6304t
Subscribe
Mbd6304t Firmware
Subscribe
Nbd6808t-pl
Subscribe
Nbd6808t-pl Firmware
Subscribe
Nbd7004t-p
Subscribe
Nbd7004t-p Firmware
Subscribe
Nbd7008t-p
Subscribe
Nbd7008t-p Firmware
Subscribe
Nbd7016t-f-v2
Subscribe
Nbd7016t-f-v2 Firmware
Subscribe
Nbd7024h-p
Subscribe
Nbd7024h-p Firmware
Subscribe
Nbd7024t-p
Subscribe
Nbd7024t-p Firmware
Subscribe
Nbd7804r-f\(ep\)
Subscribe
Nbd7804r-f\(ep\) Firmware
Subscribe
Nbd7804r-f\(hdmi\)
Subscribe
Nbd7804r-f\(hdmi\) Firmware
Subscribe
Nbd7804r-fw
Subscribe
Nbd7804r-fw Firmware
Subscribe
Nbd7804t-pl
Subscribe
Nbd7804t-pl Firmware
Subscribe
Nbd7808r-pl\(ep\)
Subscribe
Nbd7808r-pl\(ep\) Firmware
Subscribe
Nbd7808r-pl\(hdmi\)
Subscribe
Nbd7808r-pl\(hdmi\) Firmware
Subscribe
Nbd7808t-pl
Subscribe
Nbd7808t-pl Firmware
Subscribe
Nbd7904r-fs
Subscribe
Nbd7904r-fs Firmware
Subscribe
Nbd7904t-p
Subscribe
Nbd7904t-p Firmware
Subscribe
Nbd7904t-pl
Subscribe
Nbd7904t-pl-xpoe
Subscribe
Nbd7904t-pl-xpoe Firmware
Subscribe
Nbd7904t-pl Firmware
Subscribe
Nbd7904t-plc-xpoe
Subscribe
Nbd7904t-plc-xpoe Firmware
Subscribe
Nbd7904t-q
Subscribe
Nbd7904t-q Firmware
Subscribe
Nbd7908t-q
Subscribe
Nbd7908t-q Firmware
Subscribe
Nbd8004r-pl\(ep\)
Subscribe
Nbd8004r-pl\(ep\) Firmware
Subscribe
Nbd8004r-yl\(ep\)
Subscribe
Nbd8004r-yl\(ep\) Firmware
Subscribe
Nbd8004t-q
Subscribe
Nbd8004t-q Firmware
Subscribe
Nbd8008r-pl
Subscribe
Nbd8008r-pl\(ep\)
Subscribe
Nbd8008r-pl\(ep\) Firmware
Subscribe
Nbd8008r-pl Firmware
Subscribe
Nbd8008r-yl\(ep\)
Subscribe
Nbd8008r-yl\(ep\) Firmware
Subscribe
Nbd8008ra-gl
Subscribe
Nbd8008ra-gl Firmware
Subscribe
Nbd8008ra-glk
Subscribe
Nbd8008ra-glk Firmware
Subscribe
Nbd8008ra-ul\(ep\)
Subscribe
Nbd8008ra-ul\(ep\) Firmware
Subscribe
Nbd8008ra-ula
Subscribe
Nbd8008ra-ula Firmware
Subscribe
Nbd8008ra-ulk
Subscribe
Nbd8008ra-ulk Firmware
Subscribe
Nbd8008t-q
Subscribe
Nbd8008t-q Firmware
Subscribe
Nbd8009s-ula-v2
Subscribe
Nbd8009s-ula-v2 Firmware
Subscribe
Nbd8010s-kl-v2
Subscribe
Nbd8010s-kl-v2 Firmware
Subscribe
Nbd8016r-ul
Subscribe
Nbd8016r-ul Firmware
Subscribe
Nbd8016ra-k\(ep\)
Subscribe
Nbd8016ra-k\(ep\) Firmware
Subscribe
Nbd8016ra-ul
Subscribe
Nbd8016ra-ul\(ep\)
Subscribe
Nbd8016ra-ul\(ep\) Firmware
Subscribe
Nbd8016ra-ul Firmware
Subscribe
Nbd8016ra-ula
Subscribe
Nbd8016ra-ula Firmware
Subscribe
Nbd8016ra-ulk
Subscribe
Nbd8016ra-ulk Firmware
Subscribe
Nbd8016s-kl-v2
Subscribe
Nbd8016s-kl-v2 Firmware
Subscribe
Nbd8016s-ula-v2
Subscribe
Nbd8016s-ula-v2 Firmware
Subscribe
Nbd8016t-q-v2
Subscribe
Nbd8016t-q-v2 Firmware
Subscribe
Nbd8025r-ul
Subscribe
Nbd8025r-ul Firmware
Subscribe
Nbd8032h4-p
Subscribe
Nbd8032h4-p Firmware
Subscribe
Nbd8032h4-q
Subscribe
Nbd8032h4-q Firmware
Subscribe
Nbd8032h4-qe
Subscribe
Nbd8032h4-qe Firmware
Subscribe
Nbd8032h4-ul
Subscribe
Nbd8032h4-ul Firmware
Subscribe
Nbd8032h8-p
Subscribe
Nbd8032h8-p Firmware
Subscribe
Nbd8032h8-qe
Subscribe
Nbd8032h8-qe Firmware
Subscribe
Nbd8032ra-ul-v2
Subscribe
Nbd8032ra-ul-v2 Firmware
Subscribe
Nbd8064h8-p
Subscribe
Nbd8064h8-p Firmware
Subscribe
Nbd80n16ra-kl
Subscribe
Nbd80n16ra-kl\(ep\)
Subscribe
Nbd80n16ra-kl\(ep\) Firmware
Subscribe
Nbd80n16ra-kl Firmware
Subscribe
Nbd80s08s-kl\(ep\)
Subscribe
Nbd80s08s-kl\(ep\) Firmware
Subscribe
Nbd80s10s-kl
Subscribe
Nbd80s10s-kl Firmware
Subscribe
Nbd80s16s-kl
Subscribe
Nbd80s16s-kl\(ep\)
Subscribe
Nbd80s16s-kl\(ep\) Firmware
Subscribe
Nbd80s16s-kl Firmware
Subscribe
Nbd80x09ra-kl
Subscribe
Nbd80x09ra-kl Firmware
Subscribe
Nbd80x09s-kl
Subscribe
Nbd80x09s-kl Firmware
Subscribe
Nbd88x09s-kl
Subscribe
Nbd88x09s-kl Firmware
Subscribe
Nbd8904r-pl
Subscribe
Nbd8904r-pl Firmware
Subscribe
Nbd8904r-yl
Subscribe
Nbd8904r-yl Firmware
Subscribe
Nbd8904t-gsc-xpoe
Subscribe
Nbd8904t-gsc-xpoe Firmware
Subscribe
Nbd8904t-q
Subscribe
Nbd8904t-q Firmware
Subscribe
Nbd8908r-pl
Subscribe
Nbd8908r-pl Firmware
Subscribe
Nbd8908r-yl
Subscribe
Nbd8908r-yl Firmware
Subscribe
Nbd8908t-pl-xpoe
Subscribe
Nbd8908t-pl-xpoe Firmware
Subscribe
Nbd8908t-plc-xpoe
Subscribe
Nbd8908t-plc-xpoe Firmware
Subscribe
Nbd8916f4-q
Subscribe
Nbd8916f4-q Firmware
Subscribe
Nbd8916f8-q
Subscribe
Nbd8916f8-q Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-47970 | Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://vulncheck.com/blog/xiongmai-iot-exploitation |
|
History
Thu, 24 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-24T20:09:06.565Z
Reserved: 2022-11-08T00:00:00.000Z
Link: CVE-2022-45045
Updated: 2024-08-03T14:01:31.484Z
Status : Modified
Published: 2022-12-01T05:15:12.043
Modified: 2025-04-24T20:15:29.603
Link: CVE-2022-45045
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD