CVE-2026-0854: Merit Lilin DH032
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
Affected products
- Merit Lilin DH032: up to and including 1.0.28.3858
- Merit Lilin DVR708: up to and including 1.3.4
- Merit Lilin DVR716: up to and including 1.3.4
- Merit Lilin DVR804: up to and including 1.3.4
- Merit Lilin DVR808: up to and including 1.3.4
- Merit Lilin DVR816: up to and including 1.3.4
- Merit Lilin NVR100L: up to and including 1.1.66
- Merit Lilin NVR1400L: up to and including 1.1.66
- Merit Lilin NVR200L: up to and including 1.1.66
- Merit Lilin NVR2400L: up to and including 1.1.66
- Merit Lilin NVR3216: up to and including 2.0.74.3921
- Merit Lilin NVR3416: up to and including 2.0.74.3921
- Merit Lilin NVR3416R: up to and including 2.0.74.3921
- Merit Lilin NVR3816: up to and including 2.0.74.3921
- Merit Lilin NVR400L: up to and including 1.1.66
- Merit Lilin NVR5104E: up to and including 4.0.24.4078
- Merit Lilin NVR5208E: up to and including 4.0.24.4078
- Merit Lilin NVR5416E: up to and including 4.0.24.4078
- Merit Lilin NVR5832: up to and including 4.0.24.4043
- Merit Lilin NVR5832S: up to and including 4.0.24.4043
Published 2026-01-12. Last modified 2026-06-17.