Vulnerability record · CVE-2016-20016 · published 19 October 2022
CVE-2016-20016: MVPower CCTV DVR web shell allows unauthenticated root command execution
Mvpower · Tv 7104he Firmware
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, ship with a web shell reachable at a /shell URI. A remote unauthenticated attacker can use it to run arbitrary operating system commands as root, and the flaw was exploited in the wild from 2017 through 2022.
Description
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerability has also been referred to as the "JAWS webserver RCE" because of the easily identifying HTTP response server field. Other firmware versions, at least from 2014 through 2019, can be affected. This was exploited in the wild in 2017 through 2022.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote root command execution with confirmed in-the-wild exploitation and a 99.7th percentile EPSS score.
What it is
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, ship with a web shell reachable at a /shell URI. A remote unauthenticated attacker can use it to run arbitrary operating system commands as root, and the flaw was exploited in the wild from 2017 through 2022.
Impact
An attacker gains root-level command execution on the device without credentials, allowing full control of the DVR and its network position.
Attack surface
Reachable over the network via HTTP requests to the /shell URI; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Exploited in the wild from 2017 to 2022 and referenced by public exploit entries (Exploit-DB 41471, Pentest Partners, Netlab 360), with a very high EPSS probability of 0.86193 (99.7th percentile); it is not listed in CISA KEV.
What to do
- Apply vendor firmware updates if available; the record does not name a fixed version, so confirm with MVPower or replace unsupported units.
- Isolate DVRs on a segmented VLAN with no internet exposure and restrict management access to trusted hosts.
- Block or filter requests to the /shell URI at the network perimeter and on internal proxies.
- Replace end-of-life MVPower DVRs that no longer receive firmware support.
- Monitor and block outbound traffic from DVR devices to prevent botnet enrollment.
Detection
- Search web or proxy logs for requests to the /shell URI.
- Identify HTTP responses with the JAWS webserver server header on CCTV/DVR hosts.
- Alert on unexpected outbound connections or command-and-control traffic originating from DVR devices.
- Monitor for suspicious processes or shell activity on DVR hosts where endpoint telemetry is available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.netlab.360.com/iot_reaper-a-rappid-spreading-new-iot-botnet-en/ | Third Party Advisory |
| https://www.exploit-db.com/exploits/41471 | ExploitThird Party AdvisoryVDB Entry |
| https://www.pentestpartners.com/security-blog/pwning-cctv-cameras/ | ExploitThird Party Advisory |
| https://blog.netlab.360.com/iot_reaper-a-rappid-spreading-new-iot-botnet-en/ | Third Party Advisory |
| https://www.exploit-db.com/exploits/41471 | ExploitThird Party AdvisoryVDB Entry |
| https://www.pentestpartners.com/security-blog/pwning-cctv-cameras/ | ExploitThird Party Advisory |
Track CVE-2016-20016 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2016-20016), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.