Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Please refer to the official advisory(M00175) to update the firmware.
Workaround
No workaround given by the vendor.
References
History
Mon, 12 Jan 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device. | |
| Title | Merit LILIN|NVR - OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-01-12T05:58:52.175Z
Reserved: 2026-01-12T03:07:24.850Z
Link: CVE-2026-0854
No data.
Status : Received
Published: 2026-01-12T06:16:11.040
Modified: 2026-01-12T06:16:11.040
Link: CVE-2026-0854
No data.
OpenCVE Enrichment
No data.
Weaknesses