Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials.
The vulnerability stems from improper credential storage (CWE-256) and exposure of sensitive system data (CWE-497). The device's configuration file is accessible without any authentication over the network, and the administrator password contained in it is not encrypted or hashed — it is stored in plaintext. An attacker can directly download this file and immediately read the login credentials.
An attacker obtains complete administrator login credentials for the device, enabling full control over the DVR recorder, including access to video streams, configuration modification, and potential use of the device as an entry point to the internal network.
Apply patches available from the manufacturer in accordance with the references (TWCERT/CC: https://www.twcert.org.tw/en/cp-139-10200-6b567-2.html). Until firmware is updated, isolate devices from the public network, restrict access to the management interface exclusively to trusted IP addresses, and block access to the configuration file at the firewall or VPN level.
Hunt Electronic hybrid DVR recorders, models HBF-09KD and HBF-16NK (specific firmware versions indicated in manufacturer references).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H