TVT NVMS-9000 Hard-coded API Credentials & Command Injection
Published Nov 24, 2025
9.3
CRITICALCVSS 4.0
EPSS 4.07%
Description
Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains hardcoded API credentials and an OS command injection flaw in its configuration services. The web/API interface accepts HTTP/XML requests authenticated with a fixed vendor credential string and passes user-controlled fields into shell execution contexts without proper argument sanitization. An unauthenticated remote attacker can leverage the hard-coded credential to access endpoints such as /editBlackAndWhiteList and inject shell metacharacters inside XML parameters, resulting in arbitrary command execution as root. The same vulnerable backend is also reachable in some models through a proprietary TCP service on port 4567 that accepts a magic GUID preface and base64-encoded XML, enabling the same command injection sink. Firmware releases from mid-February 2018 and later are reported to have addressed this issue. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-28 UTC.
Affected products
-
- Version 0StatusaffectedConstraints<mid-February firmware builds
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Shenzhen TVT Digital Technology Co., Ltd. | NVMS-9000 | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://blogs.juniper.net/en-us/threat-research/iot-botnet-exploiting-tvt-shenzhen-dvrs-still-lingers related
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-199000 Advisory
- https://github.com/mcw0/PoC/blob/master/TVT_and_OEM_IPC_NVR_DVR_RCE_Backdoor_and_Information_Disclosure.txt technical-descriptionexploit
- https://qkl.seebug.org/vuldb/ssvid-97217 exploit
- https://web.archive.org/web/20180614014914/http://en.tvt.net.cn:80/news/227.html vendor-advisorypatchmitigation
- https://www.vulncheck.com/advisories/tvt-nvms9000-hardcoded-api-credentials-and-command-injection third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://blogs.juniper.net/en-us/threat-research/iot-botnet-exploiting-tvt-shenzhen-dvrs-still-lingers | related | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-199000 | Advisory | |
| https://github.com/mcw0/PoC/blob/master/TVT_and_OEM_IPC_NVR_DVR_RCE_Backdoor_and_Information_Disclosure.txt | technical-descriptionexploit | |
| https://qkl.seebug.org/vuldb/ssvid-97217 | exploit | |
| https://web.archive.org/web/20180614014914/http://en.tvt.net.cn:80/news/227.html | vendor-advisorypatchmitigation | |
| https://www.vulncheck.com/advisories/tvt-nvms9000-hardcoded-api-credentials-and-command-injection | third-party-advisory |
Change history (0)
No recorded changes yet.