๐Ÿ” CVE Alert

CVE-2025-34132

UNKNOWN 0.0

LILIN DVR Command Injection via NTPUpdate in dvr_box

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field in the NTPUpdate configuration. The web service at /z/zbin/dvr_box fails to properly sanitize input, allowing remote attackers to inject and execute arbitrary commands as root by supplying specially crafted XML data to the DVRPOST interface.

CWE CWE-78 CWE-20
Vendor merit lilin
Product dvr firmware
Published Jul 16, 2025
Last Updated Mar 23, 2026
Stay Ahead of the Next One

Get instant alerts for merit lilin dvr firmware

Be the first to know when new unknown vulnerabilities affecting merit lilin dvr firmware are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Merit LILIN / DVR Firmware
* < 2.0b60_20200207

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
blog.netlab.360.com: https://blog.netlab.360.com/multiple-botnets-are-spreading-using-lilin-dvr-0-day/ meritlilin.com: https://www.meritlilin.com/assets/uploads/support/file/M00158-TW.pdf vulncheck.com: https://www.vulncheck.com/advisories/lilin-dvr-multiple-vulnerabilities ducklingstudio.blog.fc2.com: https://ducklingstudio.blog.fc2.com/blog-entry-400.html

Credits

360 Netlab