CVE-2018-9995 is a critical authentication bypass vulnerability affecting TBK DVR4104 and DVR4216 devices, along with numerous re-branded versions. Attackers can gain full administrative access by sending a "Cookie: uid=admin" header, allowing them to retrieve credentials and sensitive information. With a CVSS score of 9.8, this flaw is easily exploitable remotely without authentication, leading to complete compromise of confidentiality, integrity, and availability. While not officially in CISA KEV, exploit code is publicly available via ExploitDB and Nuclei templates, and there is significant community discussion and media coverage, including reports of active exploitation by malware like HiatusRAT.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:tbkvision:tbk-dvr4216_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:tbkvision:tbk-dvr4104_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.