CVE-2025-6562
Severity CVSS v4.0:
HIGH
Type:
CWE-78
OS Command Injections
Publication date:
26/06/2025
Last modified:
26/06/2025
Description
Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary OS commands and execute them on the device.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH



