CVE Feed

    Dashboard / CVE / CVE-2016-20016

    CVE-2016-20016

    MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerability has also been referred to as the "JAWS webserver RCE" because of the easily identifying HTTP response server field. Other firmware versions, at least from 2014 through 2019, can be affected. This was exploited in the wild in 2017 through 2022.

    Published:Oct 19, 2022
    Last Modified:May 9, 2025
    EPS:Oct 19, 2022
    EPSS Score:0.49419
    CVSS Score:9.8

    Affected Products

    Vendor
    Mvpower
    Product
    Tv-7104he
    Vendor
    Mvpower
    Product
    Tv-7104he Firmware
    Vendor
    Mvpower
    Product
    Tv7108he
    Vendor
    Mvpower
    Product
    Tv7108he Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High