← Vulnerability feed

Vulnerability record · CVE-2016-20016 · published 19 October 2022

CVE-2016-20016: MVPower CCTV DVR web shell allows unauthenticated root command execution

Mvpower · Tv 7104he Firmware

MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, ship with a web shell reachable at a /shell URI. A remote unauthenticated attacker can use it to run arbitrary operating system commands as root, and the flaw was exploited in the wild from 2017 through 2022.

9.8 CVSS 3.1 Critical EPSS 86% · top 0.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerability has also been referred to as the "JAWS webserver RCE" because of the easily identifying HTTP response server field. Other firmware versions, at least from 2014 through 2019, can be affected. This was exploited in the wild in 2017 through 2022.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote root command execution with confirmed in-the-wild exploitation and a 99.7th percentile EPSS score.

What it is

MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, ship with a web shell reachable at a /shell URI. A remote unauthenticated attacker can use it to run arbitrary operating system commands as root, and the flaw was exploited in the wild from 2017 through 2022.

Impact

An attacker gains root-level command execution on the device without credentials, allowing full control of the DVR and its network position.

Attack surface

Reachable over the network via HTTP requests to the /shell URI; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Exploited in the wild from 2017 to 2022 and referenced by public exploit entries (Exploit-DB 41471, Pentest Partners, Netlab 360), with a very high EPSS probability of 0.86193 (99.7th percentile); it is not listed in CISA KEV.

What to do

  • Apply vendor firmware updates if available; the record does not name a fixed version, so confirm with MVPower or replace unsupported units.
  • Isolate DVRs on a segmented VLAN with no internet exposure and restrict management access to trusted hosts.
  • Block or filter requests to the /shell URI at the network perimeter and on internal proxies.
  • Replace end-of-life MVPower DVRs that no longer receive firmware support.
  • Monitor and block outbound traffic from DVR devices to prevent botnet enrollment.

Detection

  • Search web or proxy logs for requests to the /shell URI.
  • Identify HTTP responses with the JAWS webserver server header on CCTV/DVR hosts.
  • Alert on unexpected outbound connections or command-and-control traffic originating from DVR devices.
  • Monitor for suspicious processes or shell activity on DVR hosts where endpoint telemetry is available.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-20016 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2016-20016), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.