← Vulnerability feed

Vulnerability record · CVE-2018-9995 · published 10 April 2018

CVE-2018-9995: TBK and rebranded DVR devices authentication bypass via uid cookie

Tbkvision · Tbk Dvr4216 Firmware

TBK DVR4104 and DVR4216 devices, along with numerous rebranded units (Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR/HVR/MDVR Login), accept a crafted "Cookie: uid=admin" header that bypasses authentication entirely. A remote unauthenticated attacker can then issue requests such as device.rsp?opt=user&cmd=list and receive credential data in JSON responses. The flaw exposes live video feeds and device credentials on internet-facing DVRs.

9.8 CVSS 3.0 Critical EPSS 82% · top 0.3%
9.8CVSS 3.0 base score, v2 5.0
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote authentication bypass with CVSS 9.8 and very high EPSS on internet-exposed surveillance devices makes this an urgent exposure.

What it is

TBK DVR4104 and DVR4216 devices, along with numerous rebranded units (Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR/HVR/MDVR Login), accept a crafted "Cookie: uid=admin" header that bypasses authentication entirely. A remote unauthenticated attacker can then issue requests such as device.rsp?opt=user&cmd=list and receive credential data in JSON responses. The flaw exposes live video feeds and device credentials on internet-facing DVRs.

Impact

An attacker gains full administrative access to the DVR without credentials, including user credential listings and, per the description, control over the device and its video feeds. This enables surveillance compromise and credential theft for lateral movement.

Attack surface

Reachable over the network via HTTP requests to the device web interface; no authentication is required and no user interaction is needed, as reflected by the CVSS vector AV:N/PR:N/UI:N. The attack is a single crafted cookie header on a normal device request.

Exploitation

Public exploit code and tooling are referenced (Exploit-DB 44577 and multiple Exploit-tagged advisories), and EPSS is 0.826 (99.6th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.

What to do

  • Apply vendor firmware updates for TBK DVR4104/DVR4216 and rebranded equivalents; if no patch exists, replace or isolate the device.
  • Remove DVRs from direct internet exposure; place them behind a VPN or firewall with access restricted to trusted management hosts.
  • Change default and existing credentials and audit user accounts on affected devices for unauthorized additions.
  • Disable remote/web management where not operationally required and monitor vendor advisories for rebranded models.
  • Segment DVR/NVR devices on a dedicated VLAN with no outbound or lateral access to other systems.

Detection

  • Search web/proxy logs for requests to device.rsp with opt=user&cmd=list or similar management endpoints from untrusted sources.
  • Alert on HTTP requests containing a Cookie header with uid=admin or other privileged uid values from external IPs.
  • Monitor DVR devices for anomalous authentication events, new user creation, or configuration changes.
  • Inventory internet-facing DVR/NVR devices and flag TBK and rebranded models for review.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-9995 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2018-9995), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.