CRITICAL🇵🇱 Wersja polska

CVE-2025-6561

CVSS 9.8v3.1pub. 2025-06-26upd. 2026-04-15

Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator credentials.

🤖 AI Analysis
How it works

The vulnerability stems from improper credential storage (CWE-256) and exposure of sensitive system data (CWE-497). The device's configuration file is accessible without any authentication over the network, and the administrator password contained in it is not encrypted or hashed — it is stored in plaintext. An attacker can directly download this file and immediately read the login credentials.

Impact

An attacker obtains complete administrator login credentials for the device, enabling full control over the DVR recorder, including access to video streams, configuration modification, and potential use of the device as an entry point to the internal network.

Mitigation & patch

Apply patches available from the manufacturer in accordance with the references (TWCERT/CC: https://www.twcert.org.tw/en/cp-139-10200-6b567-2.html). Until firmware is updated, isolate devices from the public network, restrict access to the management interface exclusively to trusted IP addresses, and block access to the configuration file at the firewall or VPN level.

Who is affected

Hunt Electronic hybrid DVR recorders, models HBF-09KD and HBF-16NK (specific firmware versions indicated in manufacturer references).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References