CVE-2024-7339 – TVT DVR TD-2104TS-CL queryDevInfo information disclosure
https://notcve.org/view.php?id=CVE-2024-7339
01 Aug 2024 — A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. • https://github.com/RevoltSecurities/CVE-2024-7339 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2019-20085 – TVT NVMS-1000 Directory Traversal Vulnerability
https://notcve.org/view.php?id=CVE-2019-20085
30 Dec 2019 — TVT NVMS-1000 devices allow GET /.. Directory Traversal Los dispositivos TVT NVMS-1000, permiten un Salto de Directorio de GET /.. TVT NVMS 1000 suffers from a directory traversal vulnerability. TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests. • https://www.exploit-db.com/exploits/48311 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2013-6023 – TVT TD-2308SS-B DVR - Directory Traversal
https://notcve.org/view.php?id=CVE-2013-6023
02 Nov 2013 — Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read arbitrary files via .. (dot dot) in the URI. Vulnerabilidad de salto de directorio en el DVR TVT TD-2308SS-B con firmware 3.2.0.P-3520A-00 y anteriores permite a atacantes remotos leer archivos de su elección a través de .. (punto punto) en el URI. TVT TD-2308SS-B DVR suffers from a directory traversal vulnerability. • https://www.exploit-db.com/exploits/29959 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •