CVE-2016-20016 describes a critical web shell vulnerability in MVPower CCTV DVR models, including TV-7104HE and TV7108HE, accessible via the /shell URI. This flaw allows an unauthenticated remote attacker to execute arbitrary operating system commands as root, with a CVSS score of 9.8 (CRITICAL). The vulnerability is easily exploitable due to its network attack vector and low complexity, enabling full compromise of confidentiality, integrity, and availability. This issue has been actively exploited in the wild from 2017 to 2022, with public Metasploit modules available and significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.4_115215b9CPE matchmatch criteria | cpe:2.3:o:mvpower:tv-7104he_firmware:1.8.4_115215b9:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mvpower:tv7108he_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.