>> All posts

CVE-2024-3721: TBK DVR OS command injection, swept up by botnets

The short version: TBK DVR-4104 and DVR-4216 video recorders have an OS command-injection flaw (CVE-2024-3721) that lets an attacker run commands on the device through a crafted request. A public exploit exists, and internet-facing DVRs like these are exactly what botnets hunt for. If you have one exposed, get it off the open internet. Steady hands.

At a glance

FactDetail
Our severity takeHigh — in practice (see below)
CVSS v3.1 (NVD)6.3 — Medium · AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS~86.5% · 99.7th percentile (2026-07-17)
In CISA KEV?No
Known exploited?Public exploit available; devices of this class are routinely conscripted into botnets
Vulnerability typeCWE-78 OS command injection → command execution on the device
Requires authenticated session?Per the CVSS vector, low-privilege access — but consumer DVRs commonly ship with weak or default credentials
AffectedTBK DVR-4104 and DVR-4216 up to build 20240412
Fixed inUnknown at time of writing — see vendor guidance; restrict exposure meanwhile

What you need to know

CVE-2024-3721 is an OS command injection in TBK DVR-4104 and DVR-4216 recorders. A crafted request to the device's streaming endpoint lets an attacker inject shell commands via the mdb/mdc parameters, running them on the embedded system.

The paper score understates the street reality for this class of device:

  • The barrier is thin. The vector notes low-privilege access, but budget DVRs commonly run with default or trivially guessed credentials, so in practice this is close to unauthenticated.
  • A public exploit exists, and internet-exposed DVRs/NVRs are a favorite target for automated botnet campaigns that mass-scan and mass-exploit them for command execution.
  • Compromise means device takeover — the recorder can be used for further scanning, traffic, or as a pivot on the local network.

How serious we see it

High — above the 6.3 base score.

CVSS lands it at Medium because it factors in a low-privilege requirement and per-component impact. In the field, these are internet-facing appliances with weak default authentication and a public exploit, and devices exactly like them get swept into botnets at scale — so we rate it by how it actually gets used. It isn't in KEV, which is why we don't call it Critical. The reassuring part is that the fix is squarely in your hands: these devices rarely need to be on the public internet at all.

Recommendations

  1. Get it off the public internet. Restrict management and streaming access to trusted networks or a VPN — the single highest-value step.
  2. Update the firmware. Apply the latest firmware from the vendor; confirm the running build is newer than 20240412.
  3. Change default credentials. Replace any default or weak passwords immediately.
  4. Monitor and replace. Watch for signs of compromise; retire end-of-life recorders that no longer receive fixes.
  5. Confirm your exposure first. Verify whether any TBK DVR is reachable from the internet today.

How BreachRisk sees it

BreachRisk discovers exposed devices in your external footprint the way an attacker would, fingerprints TBK DVR units, and flags exposure tied to this CVE. Where safe verification is possible, it issues a single bounded request that runs a harmless marker command and checks for it in the response — confirming the injection point exists without harming the device or leaving anything behind. That's the difference between "this looks like a vulnerable DVR" and "we confirmed the command executes."

References

See your cyber risk, proven.