Surge in Exploitation Attempts Targeting TVT NVMS DVRs: A Growing Cyber Threat

Listen to this Post

Introduction:

Cybersecurity threats continue to evolve at a rapid pace, and a recent surge in exploitation attempts targeting TVT NVMS9000 DVRs has raised alarms within the security community. These Digital Video Recorders (DVRs), commonly used in surveillance systems, are being actively targeted by attackers seeking to exploit a vulnerability disclosed in 2024. This article delves into the details of the ongoing threat, the vulnerability being exploited, and the steps users can take to mitigate the risk.

The Surge in Exploitation Attempts:

On April 3, 2025, a significant increase in exploitation attempts aimed at TVT NVMS9000 DVRs was detected. Over 2,500 unique IP addresses were observed scanning for vulnerable devices, signaling a concentrated effort by malicious actors. This wave of attacks targets an information disclosure vulnerability, first reported by SSD Advisory in May 2024. The vulnerability allows attackers to retrieve admin credentials in cleartext using a simple TCP payload, leading to an authentication bypass.

Once attackers gain administrative access, they can execute commands on the device with full privileges, effectively taking control of the DVR. According to GreyNoise, a threat monitoring platform that identified the exploit, these attacks are likely related to a Mirai-based malware strain. The malware seeks to incorporate the compromised DVRs into a botnet, enabling them to carry out further malicious activities such as proxying malicious traffic, cryptomining, and launching distributed denial of service (DDoS) attacks.

In the past month alone, GreyNoise recorded over 6,600 unique IP addresses involved in these activities, all confirmed to be malicious. The majority of these attacks originated from Taiwan, Japan, and South Korea, while the affected devices are primarily based in the United States, the United Kingdom, and Germany. The TVT NVMS9000 DVR is a product of TVT Digital Technology Co., Ltd., based in Shenzhen, China, and is widely used in security and surveillance systems.

Given the widespread use of DVRs, which are often connected to the internet, they have become prime targets for botnets. Several botnets, including HiatusRAT, Mirai, and FreakOut, have historically exploited DVR vulnerabilities, some of which date back five years. The SSD Advisory recommends that affected users upgrade their firmware to version 1.3.4 or later to resolve the issue. If upgrading is not possible, it is advised to restrict public internet access to DVR ports and block incoming requests from known malicious IP addresses listed by GreyNoise.

Signs of Mirai infections on DVRs include unusual outbound traffic, system sluggishness, frequent crashes or reboots, high CPU/memory usage even when idle, and altered configurations. If any of these symptoms are observed, users are urged to disconnect the device, perform a factory reset, update the firmware, and isolate the DVR from the main network.

The TVT NVMS9000 DVR’s last firmware update was released in 2018, raising concerns about the device’s ongoing support. This poses a challenge for users who may not be able to secure their devices with the latest patches.

What Undercode Say:

The increase in exploitation attempts on TVT NVMS9000 DVRs highlights the persistent vulnerability of IoT (Internet of Things) devices in an increasingly connected world. DVRs, which are integral to security and surveillance systems, are not immune to the evolving threat landscape. The exploitation of such devices is a prime example of how attackers are shifting their focus toward everyday technology with inadequate security measures.

The use of Mirai-based malware is particularly concerning due to the ease with which it can recruit compromised devices into a botnet. This malware has evolved over time, and its continued use demonstrates that it remains an effective tool for cybercriminals. By leveraging the vulnerabilities of these DVRs, attackers can create vast botnets capable of executing high-volume attacks, such as DDoS and cryptomining operations.

This specific vulnerability highlights a larger issue in the security of IoT devices, where manufacturers often fail to provide timely updates or discontinue support for older models. In this case, the last firmware update for the TVT NVMS9000 DVR was in 2018, leaving users vulnerable to attacks that could have been mitigated by a simple patch. For many users, especially those who rely on these devices for critical surveillance, the inability to update firmware represents a serious security risk.

The geographical spread of the attacks is also worth noting. While the majority of attacks originated from Taiwan, Japan, and South Korea, the affected devices are spread across the United States, the United Kingdom, and Germany. This global nature of the attacks shows that the risk is not confined to one region but is instead a widespread issue that requires a coordinated global response.

To address these challenges, users of affected devices must take immediate action to protect their networks. Upgrading firmware, restricting internet access to vulnerable ports, and blocking known malicious IP addresses are essential steps to mitigate the risk. However, the long-term solution lies in improving the security standards for IoT devices and encouraging manufacturers to provide regular updates and patches.

Furthermore, the use of botnets for cryptomining and DDoS attacks underscores the need for greater awareness among users and businesses about the security of their connected devices. These attacks can result in financial losses, system downtime, and reputational damage, making it crucial for organizations to prioritize IoT security as part of their overall cybersecurity strategy.

Fact Checker Results:

  1. The information disclosed by SSD Advisory in May 2024 regarding the vulnerability in TVT NVMS9000 DVRs is accurate, and the exploitation attempts observed in April 2025 align with the details provided.
  2. The connection between the Mirai botnet and the exploitation attempts has been confirmed by GreyNoise’s threat monitoring, validating the analysis of the attack’s nature.
  3. The recommendations provided, including firmware upgrades and blocking malicious IP addresses, are consistent with industry best practices for mitigating such vulnerabilities.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.linkedin.com
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image