CVE-2024-22768 describes an Improper Input Validation vulnerability affecting Hitron Systems DVR HVR-4781 versions 1.03 through 4.02, allowing network attacks when default administrator credentials are used. Rated 7.5 HIGH, this vulnerability has a low attack complexity and requires no user interaction, potentially leading to high availability impact. While not in CISA's KEV catalog, it has been observed in the wild, with reports of exploitation by the InfectedSlurs Botnet, and has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.03, < 4.03CPE matchmatch criteria | cpe:2.3:o:hitron:hvr-4781_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.