6.3
MEDIUM
CVE-2024-3721
"TBK DVR-4104/DVR-4216 File Disclosure and OS Command Injection Vulnerability"
Description

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.

INFO

Published Date :

April 13, 2024, 12:15 p.m.

Last Modified :

Nov. 21, 2024, 9:30 a.m.

Remotely Exploitable :

Yes !

Impact Score :

3.4

Exploitability Score :

2.8
Public PoC/Exploit Available at Github

CVE-2024-3721 has a 8 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2024-3721 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

References to Advisories, Solutions, and Tools

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Updated: 1 week, 1 day ago
0 stars 0 fork 0 watcher
Born at : June 15, 2025, 2:32 a.m. This repo has been linked 216 different CVEs too.

None

Updated: 3 weeks, 3 days ago
0 stars 0 fork 0 watcher
Born at : May 30, 2025, 2:59 a.m. This repo has been linked 213 different CVEs too.

None

HTML

Updated: 1 month, 2 weeks ago
0 stars 0 fork 0 watcher
Born at : May 6, 2025, 2:20 a.m. This repo has been linked 201 different CVEs too.

wy876

Python

Updated: 1 month, 3 weeks ago
3 stars 1 fork 1 watcher
Born at : April 11, 2025, 4:25 a.m. This repo has been linked 209 different CVEs too.

wy876 POC | wy876的poc仓库已删库,该项目为其仓库镜像

Updated: 1 month, 2 weeks ago
298 stars 182 fork 182 watcher
Born at : March 7, 2025, 10:17 a.m. This repo has been linked 201 different CVEs too.

备份的漏洞库,3月开始我们来维护

Updated: 1 month, 2 weeks ago
995 stars 307 fork 307 watcher
Born at : March 4, 2025, 2:54 p.m. This repo has been linked 213 different CVEs too.

漏洞文库 wiki.wy876.cn

HTML

Updated: 2 months, 1 week ago
58 stars 49 fork 49 watcher
Born at : Feb. 26, 2025, 9:46 a.m. This repo has been linked 201 different CVEs too.

Intelligence Blocklist (IPv4). DST = France & Belgium

botnets ddos ipv4 malware zombies ipaddresses malicious cyber-threat-intelligence cybersecurity

Updated: 1 month, 2 weeks ago
253 stars 33 fork 33 watcher
Born at : June 16, 2023, 4:14 p.m. This repo has been linked 8 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2024-3721 vulnerability anywhere in the article.

  • The Register
Critical Wazuh bug exploited in growing Mirai botnet infection

Cybercriminals are trying to spread multiple Mirai variants by exploiting a critical Wazuh vulnerability, researchers say – the first reported active attacks since the code execution bug was disclosed ... Read more

Published Date: Jun 10, 2025 (1 week, 6 days ago)
  • The Hacker News
Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks

A now-patched critical security flaw in the Wazur Server is being exploited by threat actors to drop two different Mirai botnet variants and use them to conduct distributed denial-of-service (DDoS) at ... Read more

Published Date: Jun 09, 2025 (2 weeks ago)
  • security.nl
Digitale videorecorders TBK aangevallen door Mirai-botnet

Digitale videorecorders van fabrikant TBK zijn het doelwit van een variant van de Mirai-malware, die besmette apparaten onderdeel maakt van een botnet. Dat laat antivirusbedrijf Kaspersky in een analy ... Read more

Published Date: Jun 09, 2025 (2 weeks ago)
  • Daily CyberSecurity
CVE-2025-4318 (CVSS 9.5): AWS Amplify RCE Flaw Exposed with PoC – CI/CD Pipelines at Risk

Image: SecureLayer7 A critical vulnerability in AWS Amplify’s UI generation tool, @aws-amplify/codegen-ui, is putting developers—and their build pipelines—at serious risk. Tracked as CVE-2025-4318, th ... Read more

Published Date: Jun 09, 2025 (2 weeks, 1 day ago)
  • The Register
US infrastructure could crumble under cyberattack, ex-NSA advisor warns

Infosec in Brief If a cyberattack hit critical infrastructure in the US, it would likely crumble, former deputy national security adviser and NSA cybersecurity director Anne Neuberger said last week. ... Read more

Published Date: Jun 08, 2025 (2 weeks, 1 day ago)
  • BleepingComputer
New Mirai botnet infect TBK DVR devices via command injection flaw

A new variant of the Mirai malware botnet is exploiting a command injection vulnerability in TBK DVR-4104 and DVR-4216 digital video recording devices to hijack them. The flaw, tracked under CVE-2024- ... Read more

Published Date: Jun 08, 2025 (2 weeks, 1 day ago)
  • Daily CyberSecurity
New Mirai Botnet Variant Targets DVR Systems via CVE-2024-3721

Kaspersky researchers have uncovered a fresh wave of attacks exploiting CVE-2024-3721 to deploy a revamped variant of the notorious Mirai botnet — and this time, the target is a vulnerable class of DV ... Read more

Published Date: Jun 08, 2025 (2 weeks, 2 days ago)
  • Kaspersky
Analysis of the latest Mirai wave exploiting TBK DVR devices with CVE-2024-3721

The abuse of known security flaws to deploy bots on vulnerable systems is a widely recognized problem. Many automated bots constantly search the web for known vulnerabilities in servers and devices co ... Read more

Published Date: Jun 06, 2025 (2 weeks, 3 days ago)
  • Cyber Security News
Routers Under Attack – Attacks Scanning for IoT & Routers at Record High

Vulnerability scanning attacks targeting internet-connected devices have surged dramatically over the past year. According to recent data compiled by F5 Labs in their February 2025 Sensor Intel Series ... Read more

Published Date: Mar 04, 2025 (3 months, 2 weeks ago)

The following table lists the changes that have been made to the CVE-2024-3721 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference https://github.com/netsecfish/tbk_dvr_command_injection
    Added Reference https://vuldb.com/?ctiid.260573
    Added Reference https://vuldb.com/?id.260573
    Added Reference https://vuldb.com/?submit.314969
  • CVE Modified by [email protected]

    May. 17, 2024

    Action Type Old Value New Value
  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • CVE Received by [email protected]

    Apr. 13, 2024

    Action Type Old Value New Value
    Added Description A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.
    Added Reference VulDB https://vuldb.com/?id.260573 [No types assigned]
    Added Reference VulDB https://vuldb.com/?ctiid.260573 [No types assigned]
    Added Reference VulDB https://vuldb.com/?submit.314969 [No types assigned]
    Added Reference VulDB https://github.com/netsecfish/tbk_dvr_command_injection [No types assigned]
    Added CWE VulDB CWE-78
    Added CVSS V2 VulDB (AV:N/AC:L/Au:S/C:P/I:P/A:P)
    Added CVSS V3.1 VulDB AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2024-3721 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
© cvefeed.io
Latest DB Update: Jun. 24, 2025 2:26