Description

A severe security flaw, CVE-2025-6561, has been identified in Hunt Electronics hybrid DVRs, leaving many surveillance systems exposed to potential attacks. The bug is in HBF-09KD and HBF-16NK DVR models using firmware V3.1.67_1786 BB11115 or lower. Security experts discovered that attackers can remotely and anonymously download the device’s configuration file, which contains administrator credentials in plain text. This allows any malicious actor with internet access to gain full administrative control of the device without needing to bypass authentication measures. The impact of this vulnerability is significant, as an attacker with administrative access can completely control the DVR. This includes the ability to modify or disable live video feeds, steal recorded footage, or use the compromised system to pivot and gain entry into the broader network infrastructure. This flaw is especially dangerous due to its ease of exploitation and its presence within a critical security system. This vulnerability not only compromises the surveillance system itself but also poses a serious risk of a large-scale breach for the entire organization. The vulnerability has a CVSS score of 9.8, highlighting the severity of the threat. Hunt Electronics has since released a patched firmware version, V3.1.70_1806 BB50604 or higher, to fix the issue. Additionally, to mitigate the risk, it is recommended that users disconnect their DVRs from the internet and disable remote access until the update is applied. After patching, it is crucial to reset all administrator account credentials and monitor for any suspicious login attempts. Taking prompt action is essential to prevent system hijacking, data theft, and further security compromises.