Exposed and Clicked: Uniview NVR XSS Vulnerability Awaits Your URL Mishap!

Uniview’s NVR301-04S2-P4 is vulnerable to cross-site scripting (XSS). Attackers can exploit this by sending malicious URLs to users, potentially executing harmful JavaScript. Update to the fixed version to mitigate risks.

Hot Take:

Uniview’s NVR is so popular, even hackers can’t resist giving it a click! It’s like the Kardashians of network video recorders—everyone’s trying to get in, but not for the right reasons!

Key Points:

  • Vulnerability: Reflected Cross-Site Scripting (XSS)
  • Affected Equipment: Uniview NVR301-04S2-P4
  • CVSS Scores: v3.1 – 5.4; v4 – 4.8
  • Discovered by Bleron Rrustemi and reported by CISA
  • Mitigation: Update to Uniview NVR-B3801.20.17.240507 or follow CISA’s defensive measures

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here