CVE-2022-45045 is an authenticated operating system command injection vulnerability in the upgrade logic of multiple Xiongmai network video recorders. A remote attacker can submit crafted JSON during an upgrade request through the service on port 34567 to execute arbitrary commands as root. Affected devices include MBD6304T firmware V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL firmware V4.02.R11.C7431119.12001.130000.00000. Exploitation has occurred since approximately 2019, with additional honeypot observations in November 2022. Vendor changes block some telnetd-based payloads but are not established to eliminate arbitrary command execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authenticated remote command-execution vulnerability in multiple Xiongmai NVR devices allows attackers to execute arbitrary operating system commands as root. Attackers connect to port 34567 and submit a crafted JSON file during an upgrade request, potentially authenticating with the default admin:tlJwpbo6 credentials. Exploitation in the wild began approximately in 2019. Since at least 2021, Xiongmai has applied patches preventing execution of telnetd through this mechanism; the content does not establish that these patches fully eliminate arbitrary command execution.
Unknown
An authenticated remote command execution flaw in the proprietary service on TCP/34567 (upgrade logic). Attackers execute shell commands (commonly to start telnetd on 9001 and sleep to hold the device), often leveraging default credentials or credential disclosure via CVE-2017-7577.
An authenticated remote command execution flaw in the proprietary service on TCP/34567 (upgrade logic). Attackers execute shell commands (commonly to start telnetd on 9001 and sleep to hold the device), often leveraging default credentials or credential disclosure via CVE-2017-7577.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.