CVE-2022-45045
Last modified
CVE-2022-45045 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. EPSS estimates a 1.24% chance of exploitation in the next 30 days.
Description
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xiongmaitech | Mbd6304t | All versions |
| Xiongmaitech | Nbd6808t-Pl | All versions |
| Xiongmaitech | Nbd7004t-P | All versions |
| Xiongmaitech | Nbd7008t-P | All versions |
| Xiongmaitech | Nbd7016t-F-V2 | All versions |
| Xiongmaitech | Nbd7024h-P | All versions |
| Xiongmaitech | Nbd7024t-P | All versions |
| Xiongmaitech | Nbd7804r-F\(Ep\) | All versions |
| Xiongmaitech | Nbd7804r-F\(Hdmi\) | All versions |
| Xiongmaitech | Nbd7804r-Fw | All versions |
| Xiongmaitech | Nbd7804t-Pl | All versions |
| Xiongmaitech | Nbd7808r-Pl\(Ep\) | All versions |
| Xiongmaitech | Nbd7808r-Pl\(Hdmi\) | All versions |
| Xiongmaitech | Nbd7808t-Pl | All versions |
| Xiongmaitech | Nbd7904r-Fs | All versions |
| Xiongmaitech | Nbd7904t-P | All versions |
| Xiongmaitech | Nbd7904t-Pl | All versions |
| Xiongmaitech | Nbd7904t-Pl-Xpoe | All versions |
| Xiongmaitech | Nbd7904t-Plc-Xpoe | All versions |
| Xiongmaitech | Nbd7904t-Q | All versions |
| Xiongmaitech | Nbd7908t-Q | All versions |
| Xiongmaitech | Nbd8004r-Pl\(Ep\) | All versions |
| Xiongmaitech | Nbd8004r-Yl\(Ep\) | All versions |
| Xiongmaitech | Nbd8004t-Q | All versions |
| Xiongmaitech | Nbd8008r-Pl | All versions |
| Xiongmaitech | Nbd8008r-Pl\(Ep\) | All versions |
| Xiongmaitech | Nbd8008r-Yl\(Ep\) | All versions |
| Xiongmaitech | Nbd8008ra-Gl | All versions |
| Xiongmaitech | Nbd8008ra-Glk | All versions |
| Xiongmaitech | Nbd8008ra-Ul\(Ep\) | All versions |
| Xiongmaitech | Nbd8008ra-Ula | All versions |
| Xiongmaitech | Nbd8008ra-Ulk | All versions |
| Xiongmaitech | Nbd8008t-Q | All versions |
| Xiongmaitech | Nbd8009s-Ula-V2 | All versions |
| Xiongmaitech | Nbd8010s-Kl-V2 | All versions |
| Xiongmaitech | Nbd8016r-Ul | All versions |
| Xiongmaitech | Nbd8016ra-K\(Ep\) | All versions |
| Xiongmaitech | Nbd8016ra-Ul | All versions |
| Xiongmaitech | Nbd8016ra-Ul\(Ep\) | All versions |
| Xiongmaitech | Nbd8016ra-Ula | All versions |
| Xiongmaitech | Nbd8016ra-Ulk | All versions |
| Xiongmaitech | Nbd8016s-Kl-V2 | All versions |
| Xiongmaitech | Nbd8016s-Ula-V2 | All versions |
| Xiongmaitech | Nbd8016t-Q-V2 | All versions |
| Xiongmaitech | Nbd8025r-Ul | All versions |
| Xiongmaitech | Nbd8032h4-P | All versions |
| Xiongmaitech | Nbd8032h4-Q | All versions |
| Xiongmaitech | Nbd8032h4-Qe | All versions |
| Xiongmaitech | Nbd8032h4-Ul | All versions |
| Xiongmaitech | Nbd8032h8-P | All versions |
Showing 50 of 144 affected configurations. See NVD for the full list.
References
- https://vulncheck.com/blog/xiongmai-iot-exploitationExploit, Technical Description, Third Party Advisory
- https://vulncheck.com/blog/xiongmai-iot-exploitationExploit, Technical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-45045?
How severe is CVE-2022-45045?
How do I fix CVE-2022-45045?
Are you affected by CVE-2022-45045?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
