Vulnerabilities

Exploitation of 5-Year-Old TBK DVR Vulnerability Spikes

Fortinet warns of a massive spike in malicious attacks targeting a five-year-old authentication bypass vulnerability in TBK DVR devices.

Fortinet warns of a massive spike in malicious attacks targeting a five-year-old authentication bypass vulnerability in TBK DVR devices.

Fortinet warns of a massive spike in exploitation attempts targeting a five-year-old authentication bypass vulnerability in TBK DVR devices.

A video surveillance company, TBK Vision provides network CCTV devices, DVRs, and other types of related equipment for protecting industrial and critical infrastructure facilities.

The vendor claims it has over 600,000 cameras, 50,000 CCTV recorders, and other devices being used by organizations in banking, government, retail, and other sectors.

Tracked as CVE-2018-9995 (CVSS score of 9.8), the issue can be exploited remotely by sending a crafted HTTP cookie, providing the attacker with administrative access to a vulnerable device. The attacker could then access camera video feeds.

Details on this critical-severity bug were published in April 2018, when security researcher Fernandez Ezequiel also published proof-of-concept (PoC) code exploiting it. To date, however, the vendor has not provided a patch to address the bug.

The issue impacts TBK’s DVR4104 and DVR4216 devices, which are also rebranded and sold under the CeNova, DVR Login, HVR Login, MDVR Login, Night OWL, Novo, QSee, Pulnix, Securus, and XVR 5 in 1 brands, a NIST advisory reads.

Advertisement. Scroll to continue reading.

According to Fortinet, during April 2023 alone, its intrusion prevention systems (IPSs) detected more than 50,000 exploitation attempts targeting CVE-2018-9995.

“With tens of thousands of TBK DVRs available under different brands, publicly-available PoC code, and an easy-to-exploit makes this vulnerability an easy target for attackers. The recent spike in IPS detections shows that network camera devices remain a popular target for attackers,” Fortinet notes.

Organizations are advised to review the CCTV cameras, DVRs, and related equipment they are using and remove any vulnerable models from their environments or ensure that they are protected by a firewall and not directly accessible from the internet.

Fortinet also observed an increase in exploitation attempts targeting a seven-year-old vulnerability in MVPower CCTV DVR models.

Tracked as CVE-2016-20016 (CVSS score of 9.8) and referred to as ‘JAWS webserver RCE’, the flaw allows an unauthenticated remote attacker to execute arbitrary system commands with root privileges.

Previously, CVE-2016-20016 was seen exploited in attacks between 2017 and 2022.

Related: New BotenaGo Variant Infects Lilin Security Cameras With Mirai

Related: CISA Adds 66 Vulnerabilities to ‘Must Patch’ List

Related: Necro Python Botnet Starts Targeting Visual Tools DVRs

Related Content

Malware & Threats

The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools.

Email Security

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.

Nation-State

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.

Vulnerabilities

The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator.

Vulnerabilities

The flaw allows attackers to send files and execute them without authorization through an active remote session.

Vulnerabilities

Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments.

Vulnerabilities

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Vulnerabilities

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version