go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Merit LILIN|NVR - OS Command Injection

TVN ID TVN-202601003
CVE ID CVE-2026-0854
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products Affected models and firmwares:

DH032:v1.0.28.3858 and earlier
DVR708, DVR716:v1.3.4 and earlier
DVR804, DVR808, DVR816:v1.3.4 and earlier
NVR100L, NVR200L, NVR400L, NVR1400L, NVR2400L:v1.1.66 and earlier
NVR3216, NVR3416, NVR3416r, NVR3816:v2.0.74.3921 and earlier
NVR5832, NVR5832S:v4.0.24.4043 and earlier
NVR5104E, NVR5208E, NVR5416E:v4.0.24.4078 and earlier
Description Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
Solution Please refer to the official advisory(M00175) to update the firmware.
Credit Li-Fan Cheng, Chih-Che Chang, Yu-Chieh Kuo, Shi-Yi Xie, Yuan-Chieh Chang, An-Wei Kung(NICS)
Public Date 2026-01-12
Top