CVE-2025-34132
LILIN DVR Command Injection via NTPUpdate in dvr_box
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the Server field in the NTPUpdate configuration. The web service at /z/zbin/dvr_box fails to properly sanitize input, allowing remote attackers to inject and execute arbitrary commands as root by supplying specially crafted XML data to the DVRPOST interface.
| CWE | CWE-78 CWE-20 |
| Vendor | merit lilin |
| Product | dvr firmware |
| Published | Jul 16, 2025 |
| Last Updated | Mar 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for merit lilin dvr firmware
Be the first to know when new unknown vulnerabilities affecting merit lilin dvr firmware are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Merit LILIN / DVR Firmware
* < 2.0b60_20200207
References
blog.netlab.360.com: https://blog.netlab.360.com/multiple-botnets-are-spreading-using-lilin-dvr-0-day/ meritlilin.com: https://www.meritlilin.com/assets/uploads/support/file/M00158-TW.pdf vulncheck.com: https://www.vulncheck.com/advisories/lilin-dvr-multiple-vulnerabilities ducklingstudio.blog.fc2.com: https://ducklingstudio.blog.fc2.com/blog-entry-400.html
Credits
360 Netlab