CVE-2025-34129
LILIN DVR RCE via Malicious FTP/NTP Configuration
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 due to insufficient sanitization of the FTP and NTP Server fields in the service configuration. An attacker with access to the configuration interface can upload a malicious XML file with injected shell commands in these fields. Upon subsequent configuration syncs, these commands are executed with elevated privileges. This vulnerability was exploited in the wild by the Moobot botnets.
| CWE | CWE-78 CWE-20 |
| Vendor | merit lilin |
| Product | dvr firmware |
| Published | Jul 16, 2025 |
| Last Updated | Mar 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for merit lilin dvr firmware
Be the first to know when new unknown vulnerabilities affecting merit lilin dvr firmware are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Merit LILIN / DVR Firmware
* < 2.0b60_20200207
References
Credits
360 Netlab