CVE-2025-7724
Unauthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.
| CWE | CWE-78 |
| Vendor | tp-link systems inc. |
| Product | vigi nvr1104h-4p v1 |
| Published | Jul 22, 2025 |
| Last Updated | Feb 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. vigi nvr1104h-4p v1
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. vigi nvr1104h-4p v1 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
TP-Link Systems Inc. / VIGI NVR1104H-4P V1
0 < 1.1.5 Build 250518
TP-Link Systems Inc. / VIGI NVR2016H-16MP V2
0 < 1.3.1 Build 250407