CVE-2023-7227: Systemk-Corp NVR 504 Firmware

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privileges.

Affected products

  • Systemk-Corp NVR 504 Firmware: version 2.3.5sk.30084998 only
  • Systemk-Corp NVR 508 Firmware: version 2.3.5sk.30084998 only
  • Systemk-Corp NVR 516 Firmware: version 2.3.5sk.30084998 only

Published 2024-01-25. Last modified 2026-06-17.