CVE-2025-34129

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 due to insufficient sanitization of the FTP and NTP Server fields in the service configuration. An attacker with access to the configuration interface can upload a malicious XML file with injected shell commands in these fields. Upon subsequent configuration syncs, these commands are executed with elevated privileges. This vulnerability was exploited in the wild by the Moobot botnets.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de inyección de comandos en los dispositivos LILIN Digital Video Recorder (DVR) anteriores a la versión de firmware 2.0b60_20200207 debido a una depuración insuficiente de los campos del servidor FTP y NTP en la configuración del servicio. Un atacante con acceso a la interfaz de configuración puede cargar un archivo XML malicioso con comandos de shell inyectados en estos campos. Tras sincronizaciones de configuración posteriores, estos comandos se ejecutan con privilegios elevados. Esta vulnerabilidad fue explotada por las botnets Moobot.

17 Jul 2025, 15:15

Type Values Removed Values Added
Summary (en) A command injection vulnerability exists in LILIN LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 due to insufficient sanitization of the FTP and NTP Server fields in the service configuration. An attacker with access to the configuration interface can upload a malicious XML file with injected shell commands in these fields. Upon subsequent configuration syncs, these commands are executed with elevated privileges. This vulnerability was exploited in the wild by the Moobot botnets. (en) A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 due to insufficient sanitization of the FTP and NTP Server fields in the service configuration. An attacker with access to the configuration interface can upload a malicious XML file with injected shell commands in these fields. Upon subsequent configuration syncs, these commands are executed with elevated privileges. This vulnerability was exploited in the wild by the Moobot botnets.

16 Jul 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-16 22:15

Updated : 2026-04-15 00:35


NVD link : CVE-2025-34129

Mitre link : CVE-2025-34129

CVE.ORG link : CVE-2025-34129


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')