news.mlab.sh
Back to the feed
vulnerability

CP Plus 8 Ch. Network Video Recorder

High
Summary

A cross-site scripting (XSS) vulnerability has been identified in CP Plus 8 Ch. Network Video Recorder devices (CP-UNR-108F1 Hardware V1.0, CP-UNR-108F1 Web V3.2.7.128806, and CP-UNR-108F1 System V4.001.00AT009.0.R). Attackers can inject malicious scripts that are persistently stored on the device, potentially leading to session hijacking, unauthorized actions, and data theft. The vulnerability stems from insufficient input sanitization and is being addressed through firmware updates.

This vulnerability, classified as CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), affects devices deployed in commercial facilities, critical manufacturing, and emergency services sectors. The devices are currently used in India, Nepal, the United Arab Emirates, and Gambia, with CP Plus headquarters located in India. The vulnerability allows an attacker to execute scripts within the browser of authenticated users or administrators accessing the device's interface. This could result in the compromise of user sessions, enabling unauthorized actions with the victim's privileges, or the exposure and manipulation of sensitive data. CISA recommends immediate action, urging users to update their firmware to the latest version (CP-UNR-AxxxMars_PN_15_Q_00_V1.00.14.01.T.260326) to mitigate the risk. Furthermore, CISA is advising organizations to implement defensive measures such as minimizing network exposure, isolating control systems behind firewalls, and utilizing secure remote access methods like VPNs.

Read the full article at CISA Advisories