White Rabbitx[verified]@TheRabbitPyDisclosure
The text announces vulnerability CVE‑2026‑34005 in Xiongmai DVR/NVRs that allows authenticated admins to inject shell metacharacters via the HostName field, potentially resulting in system compromise.
Ukycircle@UkyKnightDisclosure
A new OS command injection vulnerability (CVE‑2026‑34005) was reported in Xiongmai DVR/NVR firmware V4.03.R11, with technical notes provided but no PoC, exploit, or patch details disclosed.
CVE@CVEnewDisclosure
The post discloses a root OS command‑injection flaw on specific Xiongmai DVR/NVR models, noting the vulnerability occurs when shell metacharacters are used in the HostName field; it provides no PoC, exploit details, patches, or evidence of active exploitation.
VulDB 🛡@vuldbActive Exploitation
The CTI team observed multiple attacks against Xiongmai devices using CVE-2026-34005, indicating the vulnerability is actively exploited in the wild.
VulDB 🛡@vuldbDisclosure
The post announces that CVE-2026-34005 has been added to a vulnerability database, affecting Xiongmai AHB7008T-MH-V2 and NBD7024H-P devices.
The Hacker Wire@TheHackerWireGeneral
The tweet highlights a root OS command injection flaw in specific Xiongmai DVR/NVR models, providing technical details but no evidence of active exploitation, patch, or PoC.
CVEFind.com@CveFindComDisclosure
The post announces that Xiongmai DVR/NVR devices in Sofia are vulnerable to root OS command injection via authenticated DVRIP requests and urges users to apply security patches.