Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-34005

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Mar 29, 2026
Vendor unknown

Description

In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (TCP port 34567) request to the NetWork.NetCommon configuration handler, because system() is used.

References