WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Vulnerability Awareness – Spike in Attacks against CCTV Products with Critical Five-Year-Old Vulnerability
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Vulnerability Awareness – Spike in Attacks against CCTV Products with Critical Five-Year-Old Vulnerability

Author: April Zupan

Created: Tuesday, May 2, 2023 - 17:47

Categories: Cybersecurity, OT-ICS Security

Security Week has written an article discussing a spike in attacks exploiting CVE-2018-9995, a 5 year old critical authentication bypass vulnerability in TBK Vision devices, and CVE-2016-20016, a 7 year old vulnerability in MVPower devices. Reported by Fortinet, both of these manufacturers produce CCTV equipment often used to protect critical infrastructure facilities, with TBK Vision claiming it’s deployed “over 600,000 cameras, 50,000 CCTV recorders, and other devices being used by organizations in banking, government, retail, and other sectors.” Reportedly, the vulnerability impacts the following products – TBK’s DVR4104 and DVR4216 devices, which are also rebranded and sold under the CeNova, DVR Login, HVR Login, MDVR Login, Night OWL, Novo, QSee, Pulnix, Securus, and XVR 5 in 1 brands. FortiGuard Labs is not aware of any patches provided by the vendor and recommends organizations review installed models of CCTV camera systems and related equipment for vulnerable models.

Members who utilize the impacted products are highly encouraged to review available reporting and address accordingly. This spike in detection and exploitation attempts is another example of how insecure IoT devices persist, as both CVEs still do not have a patch available, and, as Fortinet notes, why “network camera devices remain a popular target for attackers.” Read more at Security Week.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar