216.73.217.22

CVE-2025-7724

· Published 22/07/2025 21:15 · Modified 23/07/2025 16:15

Labels: CVE-2025-7724 2025-07-22CVE-2025-7724CWE-78f23511db-6c3e-4e32-a477-6aa17d310630

Essential information

Published
22/07/2025 21:15
Modified
23/07/2025 16:15
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
f23511db-6c3e-4e32-a477-6aa17d310630
NVD
View on NVD

Affected products (CPE)

ProductCPE
vigi / nvr1104h-4p cpe:2.3:a:vigi:nvr1104h-4p:1.1.5:*:*:*:*:*:*:*
vigi / nvr2016h-16mp cpe:2.3:a:vigi:nvr2016h-16mp:1.3.1:*:*:*:*:*:*:*

References