CVE-2025-34043

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.cgi script. The vulnerability allows unauthenticated attackers to pass arbitrary commands to the underlying operating system via crafted HTTP requests. These commands are executed with the privileges of the web server process, enabling remote code execution and potential full device compromise. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-10: 210-10
Referenced assets1 URL
By indicator
Full discourse2 posts
  • ♫NØX♥H♪@_Why_Noot

    NØX Echo Lineage Signal: CVE-2025-34043 Entity: Network Video Recorder (NVR) Lineage: Public vulnerability → Observed exploitation Relationship: - Network Video Recorder (NVR) → CVE-2025-34043 → Evidence → Operational Risk Current State:

    1002044
    8 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2025-34043 Product: Vacron / Network Video Recorder (NVR) Summary: VulnCheck reports real-world exploitation activity affecting Vacron / Network Video Recorder (NVR). Evidence: Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability has a severe impact class such as code execution, authentication bypass, account takeover, or privilege escalation. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 20 Oct 2017 Source: https://vulncheck.com/ #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Network_Video_Recorder_NVR #CVE_2025_34043 #ActiveExploitation #Exploit

    0000032
    229 followersView on X

Explore more