Security for everyone

CVE-2018-9995 Scanner

Detects 'Authentication Bypass' vulnerability in TBK DVR4104 and DVR4216 devices affects v. Unknown.

SCAN NOW

Short Info


Level

Critical

Type

Single Scan

Can be used by

Asset Owner

Estimated Time

10 sec

Scan only one

Url

Parent Category

CVE-2018-9995 Scanner Detail

The TBK DVR4104 and DVR4216 devices are popular surveillance devices used for monitoring, recording, and managing video feeds in various settings like offices, homes, schools, and warehouses. However, these devices have been found to be vulnerable to a severe security flaw, CVE-2018-9995, which can allow remote attackers to bypass authentication.

The CVE-2018-9995 vulnerability is caused by a "Cookie: uid=admin" header that allows attackers to bypass authentication via a device.rsp?opt=user&cmd=list request. This request provides credentials within JSON data in a response, thereby allowing attackers to gain access to sensitive data.

When exploited, this vulnerability can lead to dire consequences like unauthorized access to video feeds, loss and theft of sensitive data, device hijacking, and compromised security systems. Attackers can easily take over the device remotely and use it for various malicious activities like spying, data theft, and DDoS attacks.

At SecurityForEveryone.com, we understand the importance of staying up to date with the latest security vulnerabilities and threats that can affect your digital assets. With our professional platform, users can quickly and easily learn about vulnerabilities in their digital assets and take appropriate action to protect them. Don't wait until it's too late - sign up for SecurityForEveryone.com today.

 

REFERENCES

cyber security services for everyone one. Free security tools, continuous vulnerability scanning and many more.
Try it yourself,
control security posture