Medium severity5.3NVD Advisory· Published Aug 24, 2023· Updated Jun 17, 2026
CVE-2023-3704
CVE-2023-3704
Description
The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device.
Successful exploitation of this vulnerability could allow the remote attacker to change system time of the targeted device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- cpe:2.3:o:cpplusworld:cp-uvr-0401l1-4kh_firmware:*:*:*:*:*:*:*:*Range: <4.000.00at008.0.0.r20230302
- cpe:2.3:o:cpplusworld:cp-uvr-0401l1b-4kh_firmware:*:*:*:*:*:*:*:*Range: <4.000.00at008.0.0.r20230302
- cpe:2.3:o:cpplusworld:cp-uvr-0801f1-hc_firmware:*:*:*:*:*:*:*:*Range: <4.000.00at008.0.0.r20230302
- cpe:2.3:o:cpplusworld:cp-uvr-0801k1-h_firmware:*:*:*:*:*:*:*:*Range: <4.000.00at008.0.0.r20230302
- cpe:2.3:o:cpplusworld:cp-uvr-0801k1b-h_firmware:*:*:*:*:*:*:*:*Range: <4.000.00at008.0.0.r20230302
- cpe:2.3:o:cpplusworld:cp-uvr-0808k1-h_firmware:*:*:*:*:*:*:*:*Range: <4.000.00at008.0.0.r20230302
- cpe:2.3:o:cpplusworld:cp-uvr-1601e1-h_firmware:*:*:*:*:*:*:*:*Range: <4.000.00at008.0.0.r20230302
- cpe:2.3:o:cpplusworld:cp-uvr-1601e1-hc_firmware:*:*:*:*:*:*:*:*Range: <4.000.00at008.0.0.r20230302
- cpe:2.3:o:cpplusworld:cp-uvr-1601e2-h_firmware:*:*:*:*:*:*:*:*Range: <4.000.00at008.0.0.r20230302
- Aditya Infotech Limited/CP-UVR-1601E1-HC, CP-UVR-1601E2-H, CP-UVR-1601E1-H, CP-UVR-0801F1-HC, CP-UVR-0801K1-H, CP-UVR-0801K1B-H, CP-UVR-0808K1-H, CP-UVR-0401L1-4KH, CP-UVR-0401L1B-4KHv5Range: 0
Patches
Vulnerability mechanics
References
1- www.cert-in.org.in/s2cMainServletnvdVendor Advisory
News mentions
0No linked articles in our index yet.