Impact
Certain KGUARD DVR devices expose a command execution service on all network interfaces without authentication. A remote attacker with network access can run arbitrary system commands, leading to full compromise of the device. The flaw stems from improper input validation and processing (CWE‑1188).
Affected Systems
Affected devices include KGUARD firmware appliances such as D1004NR, D1008NR, D1016NR, D1104, D1104NR, D1108NR, D1116NR, D1132NR, D2116NR, D97xx, D98xx, and D99xx variants. Firmware dated from 2016 is vulnerable; versions released after 2017 mitigate the issue by limiting the service to localhost.
Risk and Exploitability
The vulnerability carries a CVSS score of 10. It has been actively exploited by the Mirai_ptea (Rimasuta) and Mirai_aurora botnets for malware distribution and DDoS attacks. The EPSS score is 1%, indicating a low but nonzero probability of exploitation, and the lack of a KEV listing does not reduce the observed exploitation. Any network host with access to the exposed service can execute arbitrary commands, giving the attacker complete control over the DVR.
OpenCVE Enrichment