S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-9995 Scanner

Detects 'Authentication Bypass' vulnerability in TBK DVR4104 and DVR4216 devices affects v. Unknown.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-9995
9.8
CVSS

TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 18, 2026View on NVD →
Detail

The TBK DVR4104 and DVR4216 devices are popular surveillance devices used for monitoring, recording, and managing video feeds in various settings like offices, homes, schools, and warehouses. However, these devices have been found to be vulnerable to a severe security flaw, CVE-2018-9995, which can allow remote attackers to bypass authentication.

The CVE-2018-9995 vulnerability is caused by a "Cookie: uid=admin" header that allows attackers to bypass authentication via a device.rsp?opt=user&cmd=list request. This request provides credentials within JSON data in a response, thereby allowing attackers to gain access to sensitive data.

When exploited, this vulnerability can lead to dire consequences like unauthorized access to video feeds, loss and theft of sensitive data, device hijacking, and compromised security systems. Attackers can easily take over the device remotely and use it for various malicious activities like spying, data theft, and DDoS attacks.

At s4e.io, we understand the importance of staying up to date with the latest security vulnerabilities and threats that can affect your digital assets. With our professional platform, users can quickly and easily learn about vulnerabilities in their digital assets and take appropriate action to protect them. Don't wait until it's too late - sign up for s4e.io today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, experts suggest taking the following precautions:

  • Disable remote access to the device unless absolutely necessary.
  • Disable or block the default ports used by the device and switch to non-standard ports for better security.
  • Update the device's firmware to the latest version with all the necessary security patches.
  • Ensure strong and complex passwords are set for all user accounts and change them frequently.
  • Monitor network traffic closely for signs of suspicious activity and block unauthorized access attempts immediately.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-9995 scanner - Authentication Bypass vulnerability in TBK DVR4104 and DVR4216 devices | S4E