CVE Feed

    Dashboard / CVE / CVE-2026-34005

    CVE-2026-34005

    In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (TCP port 34567) request to the NetWork.NetCommon configuration handler, because system() is used.

    Published:Mar 29, 2026
    Last Modified:Jun 17, 2026
    EPS:Mar 29, 2026
    EPSS Score:0.01539
    CVSS Score:8.8

    Affected Products

    Vendor
    Xiongmai
    Product
    Dvr/nvr Devices

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High