CVE-2026-34005 HIGH

CVE-2026-34005

Vendor Xiongmai
Product DVR/NVR devices
Weakness CWE-78
Published March 29, 2026
Last update March 30, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (TCP port 34567) request to the NetWork.NetCommon configuration handler, because system() is used.

Key dates

02Disclosure timeline

March 29, 2026 CVE published
March 30, 2026 Record updated