High severity8.8NVD Advisory· Published Mar 29, 2026· Updated Apr 27, 2026
CVE-2026-34005
CVE-2026-34005
Description
In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (TCP port 34567) request to the NetWork.NetCommon configuration handler, because system() is used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: = 4.03.R11
- Range: = 4.03.R11
- Range: = 4.03.R11
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.