VIGI NVR Command Injection Vulnerability

Vulnerability

A command injection vulnerability allowing unauthenticated OS command execution exists in the VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2 models. For VIGI NVR1104H-4P V1, this vulnerability affects versions prior to 1.1.5 Build 250518. For VIGI NVR2016H-16MP V2, the vulnerable versions are prior to 1.3.1 Build 250407.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the device's operating system.

Remediation

Users are advised to update to VIGI NVR1104H-4P V1 version 1.1.5 Build 250518 or VIGI NVR2016H-16MP V2 version 1.3.1 Build 250407. The latest firmware for both models can be downloaded from the TP-Link VIGI support website.

Added: Jul 22, 2025, 9:58 PM
Updated: Jul 22, 2025, 9:58 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.