Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device.
Metrics
Affected Vendors & Products
Fixes
Solution
Update firmware version to x.x.x.79 and later
Workaround
No workaround given by the vendor.
References
History
Fri, 12 Sep 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device. | |
Title | Digiever|NVR - OS Command Injection | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-09-12T10:15:46.072Z
Reserved: 2025-09-11T11:42:43.481Z
Link: CVE-2025-10265

No data.

Status : Received
Published: 2025-09-12T11:15:30.340
Modified: 2025-09-12T11:15:30.340
Link: CVE-2025-10265

No data.

No data.