CVE-2025-36529: Tb-Eye Ltd Hrx-1621/te

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who is logging in to the device.

Affected products

  • Tb-Eye Ltd Hrx-1621/te: up to and including 3.05.62
  • Tb-Eye Ltd Hrx-1635/te: up to and including 5.31.72
  • Tb-Eye Ltd Hrx-421fn/te: up to and including 3.05.62
  • Tb-Eye Ltd Hrx-435fn/te: up to and including 5.31.72
  • Tb-Eye Ltd Hrx-821/te: up to and including 3.05.62
  • Tb-Eye Ltd Hrx-835/te: up to and including 5.31.72
  • Tb-Eye Ltd Prn-4011n/te: up to and including 2.51p_231208081715
  • Tb-Eye Ltd Xrn-1610sn/te: up to and including 2.47b_210516234524
  • Tb-Eye Ltd Xrn-1620s/te: up to and including 5.34.12
  • Tb-Eye Ltd Xrn-3210r/te: up to and including 5.34.12
  • Tb-Eye Ltd Xrn-410sn/te: up to and including 2.47b_220119153805
  • Tb-Eye Ltd Xrn-425sfn/te: up to and including 5.31.32
  • Tb-Eye Ltd Xrn-426s: up to and including 5.33.12
  • Tb-Eye Ltd Xrn-6410dr/te: up to and including 5.34.12
  • Tb-Eye Ltd Xrn-6410r/te: up to and including 5.34.12
  • Tb-Eye Ltd Xrn-810sn/te: up to and including 2.47b_220119153805
  • Tb-Eye Ltd Xrn-820s/te: up to and including 5.34.12

Published 2025-06-27. Last modified 2026-06-17.