CVE Explorer
CVE-2026-34005
In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters in the HostName value via an authenticated DVRIP protocol (TCP port 34567) request to the NetWork.NetCommon configuration handler, because system() is used.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","modules":["Sofia binary - hostname configuration handler"],"product":"DVR/NVR devices","vendor":"Xiongmai","versions":[{"status":"affected","version":"4.03.R11","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4253a28e6db23d022d94417fa3e87c59336e51e6dd46c5412cd0ea77dbf1bc12 · sha256:2f145b5673f884f2… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4253a28e6db23d022d94417fa3e87c59336e51e6dd46c5412cd0ea77dbf1bc12 · sha256:2f145b5673f884f2… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-78","description":"CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4253a28e6db23d022d94417fa3e87c59336e51e6dd46c5412cd0ea77dbf1bc12 · sha256:2f145b5673f884f2… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"https://uky007.github.io/CVE-2026-34005/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4253a28e6db23d022d94417fa3e87c59336e51e6dd46c5412cd0ea77dbf1bc12 · sha256:2f145b5673f884f2… · /containers/cna/references/1
{"url":"https://www.xiongmaitech.com"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4253a28e6db23d022d94417fa3e87c59336e51e6dd46c5412cd0ea77dbf1bc12 · sha256:2f145b5673f884f2… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.