A command injection vulnerability exists in LILIN Digital...
Critical severity
Unreviewed
Published
Jul 17, 2025
to the GitHub Advisory Database
•
Updated Jul 17, 2025
Description
Published by the National Vulnerability Database
Jul 16, 2025
Published to the GitHub Advisory Database
Jul 17, 2025
Last updated
Jul 17, 2025
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field in the NTPUpdate configuration. The web service at /z/zbin/dvr_box fails to properly sanitize input, allowing remote attackers to inject and execute arbitrary commands as root by supplying specially crafted XML data to the DVRPOST interface. 777
References