go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Digiever|NVR - 2 Vulnerabilities

TVN ID TVN-202509001
CVE ID CVE-2025-10264, CVE-2025-10265
CVSS CVE-2025-10264:
10 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVE-2025-10265:
8.8 (High) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products Affected NVR series:
DS-1200
DS-2100 Pro
DS-2100 Pro+
DS-2100 UHD
DS-2200 UHD
DS-2200 UHD+
DS-4200 Pro
DS-4200 Pro+
DS-4200 UHD
DS-4200 UHD+
DS-4100-RM
DS-4200-RM Pro+
DS-4200-RM UHD
DS-8x00-RM Pro+
DS-8x00-SRM Pro+
DS-8x00-RM UHD
DS-16x00-RM Pro+
DS-16x00-RM UHD

Affected Firmware version:
x.x.x.78(含)以前版本
Description CVE-2025-10264(Exposure of Sensitive Information):
Unauthenticated remoter attackers can access the system configuration file and obtain plaintext credentials of the NVR and its connected cameras.

CVE-2025-10265(OS Command Injection):
Authenticated remote attackers can inject arbitrary OS commands and execute them on the device.
Solution Update firmware version to x.x.x.79 and later
Credit Yu-Chieh Kuo, Li-Fan Cheng, Zhen-Gao Liu, Shi-Yi Xie, Chih-Che Chang, An-Wei Kung(NICS)
Public Date 2025-09-11
Top