Vulnerability record · CVE-2019-20085 · published 30 December 2019
CVE-2019-20085: TVT NVMS-1000 path traversal via GET /..
Tvt · Nvms 1000 Firmware
TVT NVMS-1000 firmware is vulnerable to a directory traversal flaw reachable through a crafted GET /.. request. An unauthenticated remote attacker can read files outside the intended web root, exposing configuration and credential material on an internet-facing NVR/DVR management interface. The record does not list specific affected firmware versions.
Description
TVT NVMS-1000 devices allow GET /.. Directory Traversal
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is in CISA KEV with public exploit code and an EPSS probability above 0.96, and it exposes files on an unauthenticated network-reachable interface.
What it is
TVT NVMS-1000 firmware is vulnerable to a directory traversal flaw reachable through a crafted GET /.. request. An unauthenticated remote attacker can read files outside the intended web root, exposing configuration and credential material on an internet-facing NVR/DVR management interface. The record does not list specific affected firmware versions.
Impact
An attacker gains read access to arbitrary files on the device filesystem, which can leak stored credentials, configuration and other sensitive data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network through HTTP GET requests to the NVMS-1000 web interface; the CVSS vector shows no privileges and no user interaction required. Any host that can reach the management port can attempt it.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action deadline of 2022-05-03, and public exploit code exists in Exploit-DB and Packet Storm. EPSS 30-day probability is 0.96071 (99.874th percentile), indicating very high likelihood of exploitation activity.
What to do
- Apply the vendor update per CISA KEV required action; if no fix is available, isolate or retire the device.
- Remove NVMS-1000 management interfaces from direct internet exposure; place them behind a VPN or firewall allowlist.
- Restrict inbound access to the device's HTTP port to trusted management networks only.
- Rotate any credentials or secrets that may have been stored on or exposed by the device.
- Monitor vendor advisories for NVMS-1000 and replace end-of-life units that no longer receive firmware updates.
Detection
- Search web/proxy logs for GET requests containing '/..' or encoded traversal sequences (e.g. %2e%2e) targeting NVMS-1000 hosts.
- Alert on HTTP requests to NVMS-1000 management endpoints originating from unexpected external or non-management IP ranges.
- Review device and network logs for anomalous file-read patterns or repeated traversal attempts against the NVR/DVR interface.
- Inventory internet-exposed NVMS-1000 devices and confirm none are reachable from untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-20085 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "TVT NVMS-1000 Directory Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157196/TVT-NVMS-1000-Directory-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/47774 | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/157196/TVT-NVMS-1000-Directory-Traversal.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/47774 | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-20085 | US Government Resource |
Track CVE-2019-20085 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-20085), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.