TVT develops digital video surveillance and network storage appliances, with its vulnerability exposure centered on firmware for products such as the TD-2104TS-CL and TD-2108TS-HP series. Recurring weakness classes in this vendor's disclosures include path traversal, information exposure, and OS command injection, reflecting the network-access and administrative-interface surface typical of embedded recording and storage devices. Current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tvt over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20085HIGH TVT NVMS-1000 devices allow GET /.. Directory Traversal | Dec 30, 2019 | 7.5 | 98 | YES | YES |
CVE-2024-7339MEDIUM A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerabilit | Aug 1, 2024 | 5.3 | 46 | NO | YES |
CVE-2025-34036CRITICAL An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP ports 81 and 8 | Jun 24, 2025 | 9.8 | 44 | NO | NO |
CVE-2013-6023HIGH Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read arbitrary files via .. (dot dot) in the URI. | Nov 2, 2013 | 7.8 | 33 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tvt.
Media articles that mention a CVE ID that affects a product developed by Tvt — matched by CVE ID, not by vendor name.