VYPR
Vendor

Merit LILIN

Products
6
CVEs
7
Across products
7
Status
Private

Products

6

Recent CVEs

7
  • CVE-2022-47618CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service.

  • CVE-2021-30168CriApr 28, 2021
    risk 0.64cvss 9.8epss 0.02

    The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices.

  • CVE-2021-30167CriApr 28, 2021
    risk 0.64cvss 9.8epss 0.02

    The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices.

  • CVE-2026-0855HigJan 12, 2026
    risk 0.57cvss 8.8epss 0.01

    Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.

  • CVE-2026-0854HigJan 12, 2026
    risk 0.57cvss 8.8epss 0.01

    Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.

  • CVE-2021-30166HigApr 28, 2021
    risk 0.47cvss 7.2epss 0.04

    The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.

  • CVE-2021-30169MedApr 28, 2021
    risk 0.35cvss 5.3epss 0.02

    The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential.