CVE-2024-3721
"TBK DVR-4104/DVR-4216 File Disclosure and OS Command Injection Vulnerability"
Description
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.
INFO
Published Date :
April 13, 2024, 12:15 p.m.
Last Modified :
Nov. 21, 2024, 9:30 a.m.
Source :
[email protected]
Remotely Exploitable :
Yes !
Impact Score :
3.4
Exploitability Score :
2.8
Public PoC/Exploit Available at Github
CVE-2024-3721 has a 8 public PoC/Exploit
available at Github.
Go to the Public Exploits
tab to see the list.
Affected Products
The following products are affected by CVE-2024-3721
vulnerability.
Even if cvefeed.io
is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
No affected product recoded yet
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2024-3721
.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
None
None
None
HTML
wy876
Python
wy876 POC | wy876的poc仓库已删库,该项目为其仓库镜像
备份的漏洞库,3月开始我们来维护
漏洞文库 wiki.wy876.cn
HTML
Intelligence Blocklist (IPv4). DST = France & Belgium
botnets ddos ipv4 malware zombies ipaddresses malicious cyber-threat-intelligence cybersecurity
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2024-3721
vulnerability anywhere in the article.

-
The Register
Critical Wazuh bug exploited in growing Mirai botnet infection
Cybercriminals are trying to spread multiple Mirai variants by exploiting a critical Wazuh vulnerability, researchers say – the first reported active attacks since the code execution bug was disclosed ... Read more

-
The Hacker News
Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks
A now-patched critical security flaw in the Wazur Server is being exploited by threat actors to drop two different Mirai botnet variants and use them to conduct distributed denial-of-service (DDoS) at ... Read more

-
security.nl
Digitale videorecorders TBK aangevallen door Mirai-botnet
Digitale videorecorders van fabrikant TBK zijn het doelwit van een variant van de Mirai-malware, die besmette apparaten onderdeel maakt van een botnet. Dat laat antivirusbedrijf Kaspersky in een analy ... Read more

-
Daily CyberSecurity
CVE-2025-4318 (CVSS 9.5): AWS Amplify RCE Flaw Exposed with PoC – CI/CD Pipelines at Risk
Image: SecureLayer7 A critical vulnerability in AWS Amplify’s UI generation tool, @aws-amplify/codegen-ui, is putting developers—and their build pipelines—at serious risk. Tracked as CVE-2025-4318, th ... Read more

-
The Register
US infrastructure could crumble under cyberattack, ex-NSA advisor warns
Infosec in Brief If a cyberattack hit critical infrastructure in the US, it would likely crumble, former deputy national security adviser and NSA cybersecurity director Anne Neuberger said last week. ... Read more

-
BleepingComputer
New Mirai botnet infect TBK DVR devices via command injection flaw
A new variant of the Mirai malware botnet is exploiting a command injection vulnerability in TBK DVR-4104 and DVR-4216 digital video recording devices to hijack them. The flaw, tracked under CVE-2024- ... Read more

-
Daily CyberSecurity
New Mirai Botnet Variant Targets DVR Systems via CVE-2024-3721
Kaspersky researchers have uncovered a fresh wave of attacks exploiting CVE-2024-3721 to deploy a revamped variant of the notorious Mirai botnet — and this time, the target is a vulnerable class of DV ... Read more

-
Kaspersky
Analysis of the latest Mirai wave exploiting TBK DVR devices with CVE-2024-3721
The abuse of known security flaws to deploy bots on vulnerable systems is a widely recognized problem. Many automated bots constantly search the web for known vulnerabilities in servers and devices co ... Read more

-
Cyber Security News
Routers Under Attack – Attacks Scanning for IoT & Routers at Record High
Vulnerability scanning attacks targeting internet-connected devices have surged dramatically over the past year. According to recent data compiled by F5 Labs in their February 2025 Sensor Intel Series ... Read more
The following table lists the changes that have been made to the
CVE-2024-3721
vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by af854a3a-2127-422b-91ae-364da2661108
Nov. 21, 2024
Action Type Old Value New Value Added Reference https://github.com/netsecfish/tbk_dvr_command_injection Added Reference https://vuldb.com/?ctiid.260573 Added Reference https://vuldb.com/?id.260573 Added Reference https://vuldb.com/?submit.314969 -
CVE Modified by [email protected]
May. 17, 2024
Action Type Old Value New Value -
CVE Modified by [email protected]
May. 14, 2024
Action Type Old Value New Value -
CVE Received by [email protected]
Apr. 13, 2024
Action Type Old Value New Value Added Description A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability. Added Reference VulDB https://vuldb.com/?id.260573 [No types assigned] Added Reference VulDB https://vuldb.com/?ctiid.260573 [No types assigned] Added Reference VulDB https://vuldb.com/?submit.314969 [No types assigned] Added Reference VulDB https://github.com/netsecfish/tbk_dvr_command_injection [No types assigned] Added CWE VulDB CWE-78 Added CVSS V2 VulDB (AV:N/AC:L/Au:S/C:P/I:P/A:P) Added CVSS V3.1 VulDB AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2024-3721
is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2024-3721
weaknesses.