CVE-2025-34036 | Shenzhen TVT CCTV-DVR Cross Web Server index.html os command injection (EUVD-2025-18965 / EDB-39596)
A vulnerability was found in Shenzhen TVT CCTV-DVR. It has been declared as very critical. This vulnerability affects unknown code of the file /language/[lang]/index.html of the component Cross Web Server. The manipulation leads to os command injection.
This vulnerability was named CVE-2025-34036. The attack can be initiated remotely. Furthermore, there is an exploit available.