Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Rifatron Intelligent Digital Security System DVR Unauthenticated Live Stream Disclosure Vulnerability

Vulnerability

An unauthenticated vulnerability has been identified in the Rifatron 5brid and 7brid DVR models, specifically within the animate.cgi script. This vulnerability allows unauthorized access to live video streams through the Mobile Web Viewer module. By specifying channel numbers, attackers can retrieve sequential video snapshots without authentication. The affected DVRs include various models within the 5brid and 7brid series, running firmware versions through 8.0 (000143).

Impact

Exploitation of this vulnerability leads to unauthorized access to live video streams, allowing for the interception and storage of video data.

Reproduction

To reproduce this vulnerability, access the animate.cgi script via the Mobile Web Viewer module. Specify a channel number between 0 and 15 to request video snapshots. The snapshots can be saved and compiled into a video using tools like ffmpeg.

Added: Dec 24, 2025, 8:32 PM
Updated: Dec 24, 2025, 9:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
9.1
remediation
0.0
relevance
1.7
threat
8.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.