CVE-2024-14007
中文标题:
(暂无数据)
英文标题:
TVT NVMS-9000 < 1.3.4 Unauthenticated Administrative Queries & Information Disclosure
漏洞描述
中文描述:
(暂无数据)
英文描述:
Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions prior to 1.3.4 contain an authentication bypass in the NVMS-9000 control protocol. By sending a single crafted TCP payload to an exposed NVMS-9000 control port, an unauthenticated remote attacker can invoke privileged administrative query commands without valid credentials. Successful exploitation discloses sensitive information including administrator usernames and passwords in cleartext, network and service configuration, and other device details via commands such as queryBasicCfg, queryUserList, queryEmailCfg, queryPPPoECfg, and queryFTPCfg.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Shenzhen TVT Digital Technology Co., Ltd. | NVMS-9000 | - | < 1.3.4 | - |
cpe:2.3:a:shenzhen_tvt_digital_technology_co.,_ltd.:nvms-9000:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2024-14007 |
2025-11-26 02:02:15 | 2026-01-12 02:09:30 |
| NVD | nvd_CVE-2024-14007 |
2025-11-26 03:00:03 | 2026-01-12 02:27:10 |
版本与语言
安全公告
变更历史
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']