CVE-2018-25126 is a critical vulnerability affecting Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware, widely used in white-labeled DVR/NVR/IPC products. It combines hardcoded API credentials with an OS command injection flaw, allowing unauthenticated remote attackers to execute arbitrary commands as root. The vulnerability has a CVSS score of 9.3 (CRITICAL) due to its network-based attack vector, low complexity, and complete compromise potential. While the Shadowserver Foundation observed exploitation evidence in January 2025, there is no public exploit code available, and community discussion or media coverage is minimal. Firmware releases from mid-February 2018 and later are reported to have addressed this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Shenzhen TVT Digital Technology Co., Ltd. | NVMS-9000 | >= 0, < mid-February firmware buildsCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.