CVE-2025-34130: CWE-306 Missing Authentication for Critical Function in Merit LILIN DVR Firmware
An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin/net_html.cgi endpoint. This vulnerability allows attackers to read sensitive configuration files, such as /zconf/service.xml, which can then be used to facilitate further attacks including command injection. The vulnerability has been exploited in the wild in conjunction with other issues by botnets like FBot and Moobot.
AI Analysis
Technical Summary
This vulnerability (CVE-2025-34130) affects Merit LILIN Digital Video Recorder firmware versions before 2.0b60_20200207. It is caused by missing authentication controls on a critical function accessible through the /z/zbin/net_html.cgi endpoint, enabling unauthenticated arbitrary file reads. Attackers can retrieve sensitive configuration files, which may be leveraged to conduct additional attacks including command injection. The CVSS 4.0 base score is 8.7, reflecting network attack vector, no required privileges or user interaction, and high confidentiality impact. Exploitation has been observed in the wild in combination with other vulnerabilities by botnets like FBot and Moobot. No patch or official fix information is currently available.
Potential Impact
Successful exploitation allows unauthenticated attackers to read sensitive configuration files from affected DVR devices, compromising confidentiality. This exposure can lead to further exploitation such as command injection, increasing the risk of device takeover or network compromise. The vulnerability has been actively exploited by known botnets, indicating a real-world threat. The high CVSS score (8.7) reflects the critical nature of the confidentiality breach and ease of exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to affected DVR devices, especially blocking access to the /z/zbin/net_html.cgi endpoint from untrusted networks. Monitor for unusual activity indicative of exploitation attempts. Follow vendor communications closely for updates on patches or official mitigations.
CVE-2025-34130: CWE-306 Missing Authentication for Critical Function in Merit LILIN DVR Firmware
Description
An unauthenticated arbitrary file read exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the /z/zbin/net_html.cgi endpoint. This vulnerability allows attackers to read sensitive configuration files, such as /zconf/service.xml, which can then be used to facilitate further attacks including command injection. The vulnerability has been exploited in the wild in conjunction with other issues by botnets like FBot and Moobot.
CVSS v4.0
Score 8.7high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2025-34130) affects Merit LILIN Digital Video Recorder firmware versions before 2.0b60_20200207. It is caused by missing authentication controls on a critical function accessible through the /z/zbin/net_html.cgi endpoint, enabling unauthenticated arbitrary file reads. Attackers can retrieve sensitive configuration files, which may be leveraged to conduct additional attacks including command injection. The CVSS 4.0 base score is 8.7, reflecting network attack vector, no required privileges or user interaction, and high confidentiality impact. Exploitation has been observed in the wild in combination with other vulnerabilities by botnets like FBot and Moobot. No patch or official fix information is currently available.
Potential Impact
Successful exploitation allows unauthenticated attackers to read sensitive configuration files from affected DVR devices, compromising confidentiality. This exposure can lead to further exploitation such as command injection, increasing the risk of device takeover or network compromise. The vulnerability has been actively exploited by known botnets, indicating a real-world threat. The high CVSS score (8.7) reflects the critical nature of the confidentiality breach and ease of exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict network access to affected DVR devices, especially blocking access to the /z/zbin/net_html.cgi endpoint from untrusted networks. Monitor for unusual activity indicative of exploitation attempts. Follow vendor communications closely for updates on patches or official mitigations.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2025-04-15T19:15:22.562Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68781a21a83201eaacded28b
Added to database: 07/16/2025, 21:31:13 UTC
Last enriched: 05/21/2026, 12:07:21 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 273
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.