CVE-2026-34005Disclosure

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (TCP port 34567) request to the NetWork.NetCommon configuration handler, because system() is used.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-03-29); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-29: 4Mentions · 2026-03-30: 2Mentions · 2026-03-31: 1Active Exploitation · 2026-03-29: 1Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-29: 2Technical Details · 2026-03-30: 2Technical Details · 2026-03-31: 103-2903-3003-31
Signal classification3 categories
Disclosure
571.4%
Active Exploitation
114.3%
General
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-294
Active Exploitation1Disclosure2General1
2026-03-302
Disclosure2
2026-03-311
Disclosure1
Full discourse7 posts
  • White Rabbitx@TheRabbitPy
    Disclosure

    CVE‑2026‑34005 – Sofia‑based Xiongmai DVR/NVRs let authenticated admins inject shell metacharacters in the HostName field, turning video‑surveillance devices into rooted attack‑gateways inside the network. https://www.tenable.com/cve/CVE-2026-34005

    Post summary

    The text announces vulnerability CVE‑2026‑34005 in Xiongmai DVR/NVRs that allows authenticated admins to inject shell metacharacters via the HostName field, potentially resulting in system compromise.

    1000023
    492 followersView on X
  • Ukycircle@UkyKnight
    Disclosure

    Our first CVE-2026-34005! We reported an OS command injection issue in the Sofia binary hostname configuration handler of #Xiongmai DVR/NVR devices running firmware V4.03.R11. NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-34005 Technical note: https://uky007.github.io/CVE-2026-34005/ #cve

    Post summary

    A new OS command injection vulnerability (CVE‑2026‑34005) was reported in Xiongmai DVR/NVR firmware V4.03.R11, with technical notes provided but no PoC, exploit, or patch details disclosed.

    0000058
    11 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34005 In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via … https://www.cve.org/CVERecord?id=CVE-2026-34005

    Post summary

    The post discloses a root OS command‑injection flaw on specific Xiongmai DVR/NVR models, noting the vulnerability occurs when shell metacharacters are used in the HostName field; it provides no PoC, exploit details, patches, or evidence of active exploitation.

    0000090
    56.9K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Xiongmai AHB7008T-MH-V2 and NBD7024H-P (CVE-2026-34005) https://vuldb.com/vuln/354125/cti

    Post summary

    The CTI team observed multiple attacks against Xiongmai devices using CVE-2026-34005, indicating the vulnerability is actively exploited in the wild.

    0000091
    2.1K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Xiongmai AHB7008T-MH-V2 and NBD7024H-P (CVE-2026-34005) https://vuldb.com/vuln/354125

    Post summary

    The post announces that CVE-2026-34005 has been added to a vulnerability database, affecting Xiongmai AHB7008T-MH-V2 and NBD7024H-P devices.

    0000077
    2.1K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-34005 - High In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP pr... https://www.thehackerwire.com/vulnerability/CVE-2026-34005/ https://t.co/fwksU0XIla

    Post summary

    The tweet highlights a root OS command injection flaw in specific Xiongmai DVR/NVR models, providing technical details but no evidence of active exploitation, patch, or PoC.

    0000063
    163 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-34005: HIGH] Warning: Xiongmai DVR/NVR devices in Sofia are vulnerable to root OS command injection via authenticated DVRIP protocol request. Ensure security patches are up-to-date.#cve,CVE-2026-34005,#cybersecurity https://cvefind.com/CVE-2026-34005

    Post summary

    The post announces that Xiongmai DVR/NVR devices in Sofia are vulnerable to root OS command injection via authenticated DVRIP requests and urges users to apply security patches.

    0000062
    617 followersView on X

Explore more