CVE Database
/

CVE-2026-0854

Back to search

CVE-2026-0854

Published: Jan 12, 2026

Modified: Jan 12, 2026

PUBLISHED

CVSS v3.1

8.8

HIGH

Description

Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.

VendorProductVersions

Merit LILIN

DH032

affected
0 - <= 1.0.28.3858

Merit LILIN

DVR708

affected
0 - <= 1.3.4

Merit LILIN

DVR716

affected
0 - <= 1.3.4

Merit LILIN

DVR804

affected
0 - <= 1.3.4

Merit LILIN

DVR808

affected
0 - <= 1.3.4

Merit LILIN

DVR816

affected
0 - <= 1.3.4

Merit LILIN

NVR100L

affected
0 - <= 1.1.66

Merit LILIN

NVR200L

affected
0 - <= 1.1.66

Merit LILIN

NVR400L

affected
0 - <= 1.1.66

Merit LILIN

NVR1400L

affected
0 - <= 1.1.66

Merit LILIN

NVR2400L

affected
0 - <= 1.1.66

Merit LILIN

NVR3216

affected
0 - <= 2.0.74.3921

Merit LILIN

NVR3416

affected
0 - <= 2.0.74.3921

Merit LILIN

NVR3416r

affected
0 - <= 2.0.74.3921

Merit LILIN

NVR3816

affected
0 - <= 2.0.74.3921

Merit LILIN

NVR5832

affected
0 - <= 4.0.24.4043

Merit LILIN

NVR5832S

affected
0 - <= 4.0.24.4043

Merit LILIN

NVR5104E

affected
0 - <= 4.0.24.4078

Merit LILIN

NVR5208E

affected
0 - <= 4.0.24.4078

Merit LILIN

NVR5416E

affected
0 - <= 4.0.24.4078

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now