Vulnerability record · CVE-2018-9995 · published 10 April 2018
CVE-2018-9995: TBK and rebranded DVR devices authentication bypass via uid cookie
Tbkvision · Tbk Dvr4216 Firmware
TBK DVR4104 and DVR4216 devices, along with numerous rebranded units (Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR/HVR/MDVR Login), accept a crafted "Cookie: uid=admin" header that bypasses authentication entirely. A remote unauthenticated attacker can then issue requests such as device.rsp?opt=user&cmd=list and receive credential data in JSON responses. The flaw exposes live video feeds and device credentials on internet-facing DVRs.
Description
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote authentication bypass with CVSS 9.8 and very high EPSS on internet-exposed surveillance devices makes this an urgent exposure.
What it is
TBK DVR4104 and DVR4216 devices, along with numerous rebranded units (Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR/HVR/MDVR Login), accept a crafted "Cookie: uid=admin" header that bypasses authentication entirely. A remote unauthenticated attacker can then issue requests such as device.rsp?opt=user&cmd=list and receive credential data in JSON responses. The flaw exposes live video feeds and device credentials on internet-facing DVRs.
Impact
An attacker gains full administrative access to the DVR without credentials, including user credential listings and, per the description, control over the device and its video feeds. This enables surveillance compromise and credential theft for lateral movement.
Attack surface
Reachable over the network via HTTP requests to the device web interface; no authentication is required and no user interaction is needed, as reflected by the CVSS vector AV:N/PR:N/UI:N. The attack is a single crafted cookie header on a normal device request.
Exploitation
Public exploit code and tooling are referenced (Exploit-DB 44577 and multiple Exploit-tagged advisories), and EPSS is 0.826 (99.6th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.
What to do
- Apply vendor firmware updates for TBK DVR4104/DVR4216 and rebranded equivalents; if no patch exists, replace or isolate the device.
- Remove DVRs from direct internet exposure; place them behind a VPN or firewall with access restricted to trusted management hosts.
- Change default and existing credentials and audit user accounts on affected devices for unauthorized additions.
- Disable remote/web management where not operationally required and monitor vendor advisories for rebranded models.
- Segment DVR/NVR devices on a dedicated VLAN with no outbound or lateral access to other systems.
Detection
- Search web/proxy logs for requests to device.rsp with opt=user&cmd=list or similar management endpoints from untrusted sources.
- Alert on HTTP requests containing a Cookie header with uid=admin or other privileged uid values from external IPs.
- Monitor DVR devices for anomalous authentication events, new user creation, or configuration changes.
- Inventory internet-facing DVR/NVR devices and flag TBK and rebranded models for review.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://misteralfa-hack.blogspot.cl/2018/04/tbk-vision-dvr-login-bypass.html | ExploitThird Party Advisory |
| http://misteralfa-hack.blogspot.cl/2018/04/update-dvr-login-bypass-cve-2018-9995.html | ExploitThird Party Advisory |
| https://www.bleepingcomputer.com/news/security/new-hacking-tool-lets-users-access-a-bunch-of-dvrs-and-their-video-feeds/ | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/44577/ | ExploitThird Party AdvisoryVDB Entry |
| http://misteralfa-hack.blogspot.cl/2018/04/tbk-vision-dvr-login-bypass.html | ExploitThird Party Advisory |
| http://misteralfa-hack.blogspot.cl/2018/04/update-dvr-login-bypass-cve-2018-9995.html | ExploitThird Party Advisory |
| https://www.bleepingcomputer.com/news/security/new-hacking-tool-lets-users-access-a-bunch-of-dvrs-and-their-video-feeds/ | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/44577/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-9995 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-9995), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.