LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-34005

CVE-2026-34005 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: March 30, 2026

Sofia Xiongmai DVR/NVR - Command Injection

Published: March 29, 2026Updated: March 30, 2026PoC AvailableRemote Exploitable

Overview

Sofia Xiongmai DVR/NVR 4.03.R11 contains a command injection caused by shell metacharacters in the HostName value via authenticated DVRIP protocol request to NetWork.NetCommon configuration handler, letting authenticated attackers execute root OS commands.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 8.8%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers can execute root OS commands, potentially leading to full system compromise.

Mitigation

Update to the latest firmware version provided by the vendor.

Social Media Activity(2 posts)

Offensive Sequence
Offensive Sequence
@offseq
Mar 30, 2026

šŸ”Ž CVE-2026-34005 (HIGH): Xiongmai DVR/NVR (v4.03.R11) root OS command injection via DVRIP (port 34567). Authenticated attackers can fully compromise devices. Restrict access, monitor, and segment ASAP. https://radar.offseq.com/threat/cve-2026-34005-cwe-78-improper-neutralization-of-s-b117df4c #OffSeq #Xiongmai #Infosec #Vuln

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 29, 2026

🟠 CVE-2026-34005 - High (8.8) In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (TCP port 34567) request to the NetWork.NetCommon... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-34005/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

GitHub Repositories(1 repo)

Details

CVE ID
CVE-2026-34005
Severity
High
CVSS Score
8.8
Type
command_injection
Status
unconfirmed
EPSS
8.8%
Social Posts
2

CWE

  • CWE-78

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

8.8%Probability of exploitation in the next 30 days