6.5
MEDIUM CVSS 2.0
CVE-2024-3721
"TBK DVR-4104/DVR-4216 File Disclosure and OS Command Injection Vulnerability"
Description

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.

INFO

Published Date :

April 13, 2024, 12:15 p.m.

Last Modified :

Nov. 21, 2024, 9:30 a.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2024-3721 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 2.0 MEDIUM [email protected]
CVSS 3.1 MEDIUM [email protected]
Public PoC/Exploit Available at Github

CVE-2024-3721 has a 12 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2024-3721 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

POC on how mirai can target " CVE-2024-3721 " { TBK DVR-4104 and DVR-4216 }

Go

Updated: 3 days, 11 hours ago
0 stars 0 fork 0 watcher
Born at : Aug. 21, 2025, 2:26 a.m. This repo has been linked 1 different CVEs too.

备份的漏洞库,3月开始我们来维护

Updated: 1 month, 1 week ago
2 stars 0 fork 0 watcher
Born at : June 30, 2025, 9:14 a.m. This repo has been linked 216 different CVEs too.

None

Updated: 2 months, 1 week ago
0 stars 0 fork 0 watcher
Born at : June 15, 2025, 2:32 a.m. This repo has been linked 216 different CVEs too.

CVE POC repo 자동 수집기

Python

Updated: 13 hours, 26 minutes ago
0 stars 1 fork 1 watcher
Born at : June 8, 2025, 3:07 p.m. This repo has been linked 125 different CVEs too.

None

Updated: 2 months, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : May 30, 2025, 2:59 a.m. This repo has been linked 213 different CVEs too.

None

HTML

Updated: 3 months, 2 weeks ago
0 stars 0 fork 0 watcher
Born at : May 6, 2025, 2:20 a.m. This repo has been linked 201 different CVEs too.

wy876

Python

Updated: 1 month, 2 weeks ago
8 stars 2 fork 2 watcher
Born at : April 11, 2025, 4:25 a.m. This repo has been linked 209 different CVEs too.

wy876 POC | wy876的poc仓库已删库,该项目为其仓库镜像

Updated: 1 month ago
349 stars 196 fork 196 watcher
Born at : March 7, 2025, 10:17 a.m. This repo has been linked 201 different CVEs too.

备份的漏洞库,3月开始我们来维护

Updated: 1 month ago
1382 stars 392 fork 392 watcher
Born at : March 4, 2025, 2:54 p.m. This repo has been linked 216 different CVEs too.

漏洞文库 wiki.wy876.cn

HTML

Updated: 1 month ago
77 stars 56 fork 56 watcher
Born at : Feb. 26, 2025, 9:46 a.m. This repo has been linked 201 different CVEs too.

Data-Shield IPv4 Blocklist. DST = Europa

botnets ddos ipv4 malware ipaddresses malicious cyber-threat-intelligence cybersecurity attack-detection dnssinkhole firewall firewall-configuration firewall-rules network network-security web webapplicationfirewall blacklist-ips blocklist

Updated: 16 hours, 25 minutes ago
312 stars 38 fork 38 watcher
Born at : June 16, 2023, 4:14 p.m. This repo has been linked 13 different CVEs too.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

security cve exploit poc vulnerability

Updated: 6 hours, 56 minutes ago
7210 stars 1199 fork 1199 watcher
Born at : Dec. 8, 2019, 1:03 p.m. This repo has been linked 806 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2024-3721 vulnerability anywhere in the article.

  • Kaspersky
Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824

In April 2025, Microsoft patched 121 vulnerabilities in its products. According to the company, only one of them was being used in real-world attacks at the time the patch was released: CVE-2025-29824 ... Read more

Published Date: Aug 18, 2025 (6 days, 4 hours ago)
  • Kaspersky
Driver of destruction: How a legitimate driver is being used to take down AV processes

Introduction In a recent incident response case in Brazil, we spotted intriguing new antivirus (AV) killer software that has been circulating in the wild since at least October 2024. This malicious ar ... Read more

Published Date: Aug 06, 2025 (2 weeks, 4 days ago)
  • Kaspersky
ToolShell: a story of five vulnerabilities in Microsoft SharePoint

On July 19–20, 2025, various security companies and national CERTs published alerts about active exploitation of on-premise SharePoint servers. According to the reports, observed attacks did not requi ... Read more

Published Date: Jul 25, 2025 (4 weeks, 2 days ago)
  • The Hacker News
RondoDox Botnet Exploits Flaws in TBK DVRs and Four-Faith Routers to Launch DDoS Attacks

Cybersecurity researchers are calling attention to a malware campaign that's targeting security flaws in TBK digital video recorders (DVRs) and Four-Faith routers to rope the devices into a new botnet ... Read more

Published Date: Jul 08, 2025 (1 month, 2 weeks ago)
  • The Hacker News
RondoDox Botnet Exploits Flaws in TBK DVRs and Four-Faith Routers to Launch DDoS Attacks

Cybersecurity researchers are calling attention to a malware campaign that's targeting security flaws in TBK digital video recorders (DVRs) and Four-Faith routers to rope the devices into a new botnet ... Read more

Published Date: Jul 08, 2025 (1 month, 2 weeks ago)
  • Daily CyberSecurity
RondoDox: Sophisticated Botnet Exploits TBK DVRs & Four-Faith Routers for DDoS Attacks

RondoDox downloader shell script | Image: FortiGuard Labs FortiGuard Labs has uncovered a stealthy and highly adaptive botnet dubbed RondoDox, which is actively exploiting two critical vulnerabilities ... Read more

Published Date: Jul 05, 2025 (1 month, 2 weeks ago)
  • The Register
Critical Wazuh bug exploited in growing Mirai botnet infection

Cybercriminals are trying to spread multiple Mirai variants by exploiting a critical Wazuh vulnerability, researchers say – the first reported active attacks since the code execution bug was disclosed ... Read more

Published Date: Jun 10, 2025 (2 months, 1 week ago)
  • The Hacker News
Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks

A now-patched critical security flaw in the Wazur Server is being exploited by threat actors to drop two different Mirai botnet variants and use them to conduct distributed denial-of-service (DDoS) at ... Read more

Published Date: Jun 09, 2025 (2 months, 2 weeks ago)
  • security.nl
Digitale videorecorders TBK aangevallen door Mirai-botnet

Digitale videorecorders van fabrikant TBK zijn het doelwit van een variant van de Mirai-malware, die besmette apparaten onderdeel maakt van een botnet. Dat laat antivirusbedrijf Kaspersky in een analy ... Read more

Published Date: Jun 09, 2025 (2 months, 2 weeks ago)
  • Daily CyberSecurity
CVE-2025-4318 (CVSS 9.5): AWS Amplify RCE Flaw Exposed with PoC – CI/CD Pipelines at Risk

Image: SecureLayer7 A critical vulnerability in AWS Amplify’s UI generation tool, @aws-amplify/codegen-ui, is putting developers—and their build pipelines—at serious risk. Tracked as CVE-2025-4318, th ... Read more

Published Date: Jun 09, 2025 (2 months, 2 weeks ago)
  • The Register
US infrastructure could crumble under cyberattack, ex-NSA advisor warns

Infosec in Brief If a cyberattack hit critical infrastructure in the US, it would likely crumble, former deputy national security adviser and NSA cybersecurity director Anne Neuberger said last week. ... Read more

Published Date: Jun 08, 2025 (2 months, 2 weeks ago)
  • BleepingComputer
New Mirai botnet infect TBK DVR devices via command injection flaw

A new variant of the Mirai malware botnet is exploiting a command injection vulnerability in TBK DVR-4104 and DVR-4216 digital video recording devices to hijack them. The flaw, tracked under CVE-2024- ... Read more

Published Date: Jun 08, 2025 (2 months, 2 weeks ago)
  • Daily CyberSecurity
New Mirai Botnet Variant Targets DVR Systems via CVE-2024-3721

Kaspersky researchers have uncovered a fresh wave of attacks exploiting CVE-2024-3721 to deploy a revamped variant of the notorious Mirai botnet — and this time, the target is a vulnerable class of DV ... Read more

Published Date: Jun 08, 2025 (2 months, 2 weeks ago)
  • Kaspersky
Analysis of the latest Mirai wave exploiting TBK DVR devices with CVE-2024-3721

The abuse of known security flaws to deploy bots on vulnerable systems is a widely recognized problem. Many automated bots constantly search the web for known vulnerabilities in servers and devices co ... Read more

Published Date: Jun 06, 2025 (2 months, 2 weeks ago)
  • Cyber Security News
Routers Under Attack – Attacks Scanning for IoT & Routers at Record High

Vulnerability scanning attacks targeting internet-connected devices have surged dramatically over the past year. According to recent data compiled by F5 Labs in their February 2025 Sensor Intel Series ... Read more

Published Date: Mar 04, 2025 (5 months, 2 weeks ago)

The following table lists the changes that have been made to the CVE-2024-3721 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference https://github.com/netsecfish/tbk_dvr_command_injection
    Added Reference https://vuldb.com/?ctiid.260573
    Added Reference https://vuldb.com/?id.260573
    Added Reference https://vuldb.com/?submit.314969
  • CVE Modified by [email protected]

    May. 17, 2024

    Action Type Old Value New Value
  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • CVE Received by [email protected]

    Apr. 13, 2024

    Action Type Old Value New Value
    Added Description A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.
    Added Reference VulDB https://vuldb.com/?id.260573 [No types assigned]
    Added Reference VulDB https://vuldb.com/?ctiid.260573 [No types assigned]
    Added Reference VulDB https://vuldb.com/?submit.314969 [No types assigned]
    Added Reference VulDB https://github.com/netsecfish/tbk_dvr_command_injection [No types assigned]
    Added CWE VulDB CWE-78
    Added CVSS V2 VulDB (AV:N/AC:L/Au:S/C:P/I:P/A:P)
    Added CVSS V3.1 VulDB AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
Vulnerability Scoring Details
Base CVSS Score: 6.3
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact
Base CVSS Score: 6.5
Access Vector
Access Complexity
Authentication
Confidentiality Impact
Integrity Impact
Availability Impact