OS Command Injection Vulnerability in Hunt Electronic Hybrid DVR Models
CVE-2025-6562

8.7HIGH

Key Information:

Vendor
CVE Published:
26 June 2025

What is CVE-2025-6562?

Certain hybrid DVR models from Hunt Electronic, specifically the HBF-09KD and HBF-16NK, have been found to contain a vulnerability that allows an attacker with standard user privileges to inject arbitrary operating system commands. This weakness could potentially be exploited by malicious individuals to execute unauthorized commands on the device remotely, posing a serious risk to the integrity and security of the system.

Affected Version(s)

Hybrid DVR 0

Hybrid DVR 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6562 : OS Command Injection Vulnerability in Hunt Electronic Hybrid DVR Models