A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273262 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a Python-based exploit tool targeting CVE-2024-7339, an information leak vulnerability affecting a wide range of DVR devices. The main script, 'exploit.py', is a command-line tool that allows users to scan single or multiple URLs (provided directly or via a file) for the vulnerability. The tool sends a crafted XML payload via POST to the '/queryDevInfo' endpoint of the target device. If the device is vulnerable, it responds with sensitive information such as the kernel version, which the tool extracts and displays. The script supports multithreading, proxy usage, and output to a file. The repository includes a README with usage instructions, a requirements.txt for dependencies, and a standard MIT license. The exploit is a proof-of-concept and does not provide post-exploitation capabilities; its primary function is to detect and demonstrate the information leak. No hardcoded IPs or domains are present; the user supplies targets. The code is well-structured for scanning large numbers of devices efficiently.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.