CVE-2022-45045

Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd.
References
Link Resource
https://vulncheck.com/blog/xiongmai-iot-exploitation Exploit Technical Description
Configurations

Configuration 1

cpe:2.3:h:xiongmaitech:nbd80x09s-kl:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd80x09ra-kl:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd80n16ra-kl:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd88x09s-kl:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd80s08s-kl(ep):-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd80s16s-kl(ep):-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd80s10s-kl:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd80s16s-kl:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8016s-kl-v2:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8010s-kl-v2:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd80n16ra-kl(ep):-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8016ra-k(ep):-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8032ra-ul-v2:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8016s-ula-v2:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8009s-ula-v2:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8008ra-ul(ep):-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8016ra-ul(ep):-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8008ra-ulk:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8008ra-ula:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8904t-gsc-xpoe:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8908t-plc-xpoe:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8032h4-ul:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8908t-pl-xpoe:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7904t-plc-xpoe:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7904t-pl-xpoe:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8008ra-glk:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8016ra-ulk:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8016ra-ula:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8904r-yl:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8004r-yl(ep):-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8016ra-ul:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8008ra-gl:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8008r-yl(ep):-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd6808t-pl:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:mbd6304t:-:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8908r-yl:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8908r-pl:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8904r-pl:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8008r-pl(ep):*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8004r-pl(ep):*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8032h4-qe:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8032h8-qe:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8008r-pl:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8016r-ul:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8025r-ul:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8916f4-q:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8916f8-q:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7808r-pl(ep):*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7804r-f(ep):*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8016t-q-v2:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8064h8-p:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7016t-f-v2:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7804r-fw:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8904t-q:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8032h4-q:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8032h4-p:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8032h8-p:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8004t-q:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd8008t-q:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7904r-fs:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7904t-q:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7908t-q:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7904t-pl:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7904t-p:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7024h-p:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7804t-pl:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7808t-pl:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7024t-p:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7004t-p:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7008t-p:*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7804r-f(hdmi):*:*:*:*:*:*:*:*
cpe:2.3:h:xiongmaitech:nbd7808r-pl(hdmi):*:*:*:*:*:*:*:*

Information

Published : 2022-12-01 05:15

Updated : 2022-12-06 03:50


NVD link : CVE-2022-45045

Mitre link : CVE-2022-45045

Products Affected
No products.
CWE