Multiple Microsoft Windows Products Vulnerabilities
July 23, 2025CVE-2025-7945 – D-Link DIR-513 Vulnerability
July 23, 2025Multiple Microsoft Windows Products Vulnerabilities
July 23, 2025CVE-2025-7945 – D-Link DIR-513 Vulnerability
July 23, 2025Severity
High
Analysis Summary
CVE-2025-7724 CVSS:9.3
An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.
CVE-2025-7723 CVSS:8.5
A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.
Impact
- Gain Access
Indicators of Compromise
CVE
CVE-2025-7724
CVE-2025-7723
Affected Vendors
- TP-Link
Affected Products
- TP-Link VIGI NVR1104H-4P V1 - 1.1.5 Build 250518
- TP-Link VIGI NVR2016H-16MP V2 - 1.3.1 Build 250407
Remediation
Refer to TP-Link Security Advisory for patch, upgrade, or suggested workaround information.