Command Injection Vulnerability in LILIN Digital Video Recorders
CVE-2025-34132
What is CVE-2025-34132?
A command injection vulnerability affects LILIN Digital Video Recorder (DVR) devices before firmware version 2.0b60_20200207. This vulnerability exists due to inadequate input sanitization in the Server field of the NTPUpdate configuration. Attackers can exploit this flaw by sending specially crafted XML data to the DVRPOST interface, enabling them to execute arbitrary commands with root privileges. The compromised web service at /z/zbin/dvr_box does not sufficiently validate input, resulting in significant security risks for users of these DVR devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DVR Firmware * < 2.0b60_20200207
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
