Impact
Certain DVR/NVR models developed by Merit LILIN contain an operating‑system command injection flaw that allows an authenticated remote attacker to execute arbitrary OS commands on the device. This vulnerability permits full compromise of the affected unit, enabling the attacker to modify settings, exfiltrate data, or use the device as a pivot point for further attacks.
Affected Systems
Affected products include Merit LILIN DH032, DVR708, DVR716, DVR804, DVR808, DVR816, NVR100L, NVR1400L, NVR200L, NVR2400L, NVR3216, NVR3416, NVR3416r, NVR3816, NVR400L, NVR5104E, NVR5208E, NVR5416E, NVR5832, and NVR5832S. These units run the vendor firmware as identified in the advisory.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as high severity. The EPSS score is reported as less than 1%, suggesting a low probability of observed exploitation at this time, and it is not currently listed in the CISA KEV catalog. The attack requires remote authentication, so compromised credentials or stolen access tokens can allow an attacker to exploit the flaw. Once executed, the attacker obtains full code‑execution privileges over the device’s operating system, effectively taking control of the device.
OpenCVE Enrichment