
POC of CVE-2018-9995 written in Rust.
This repository contains a proof-of-concept (PoC) exploit implemented in Rust targeting CVE-2018-9995. The code is for research and educational purposes only.
Identifier: CVE-2018-9995
Summary: Proof-of-concept exploit demonstrating the vulnerability (see public advisories for technical details).
Rust toolchain (stable) — rustc and cargo.
Linux or any platform supported by Rust.
The repository is a PoC. Typical usage (example):
cargo run -- IP PORT
Eg:
cargo run -- 0.0.0.0 85
Defaults to port 80 if port isn't specified.
intitle:"DVR Login"
"Server GNU rsp/1.0"
"/login.rsp"
To watch live feeds from compromised CCTV cameras, you need a browser that supports ActiveX. All modern browsers have dropped support for ActiveX, so one of the few ways to watch live feeds is to use Internet Explorer. You can either install a Windows 7 VM or use "IE Mode" in Edge on Windows 10/11.
Author: 0xDamian, @damnsec1 on Twitter
References: https://nvd.nist.gov/vuln/detail/cve-2018-9995 (CVE Database), https://github.com/ezelf/CVE-2018-9995_dvr_credentials (Python POC)