important · Embedded firmware
Public emulation code routes Seetong recorder TCP/3000 commands to a root shell.
Affects
Seetong TS81xxD3X-family embedded video recorders using the iDVR 9000 firmware platform.
The extracted firmware binds the plaintext debug listener to all interfaces, and Cmd input reaches /bin/sh in a UID 0 process under emulation.
Detail and 2 sources
The researcher tested no physical recorder, so stock listener exposure and the complete model mapping remain unverified.
Chain to watch
Confirm TCP/3000 bindings on stock T8108, T8108P, T8116, and T8232 hardware.→↓Send a benign identity command through the documented Cmd protocol.→↓Record firmware build, listener interfaces, and process credentials.→↓Execution is established only against extracted firmware under emulation; stock exposure and model coverage remain unresolved.
Unverified chainTest the named stock models with a benign identity command while recording listener bindings, firmware build, and process UID.
Sources
Code / PoCGitHub - heapframe/seetong-ts81xxd3x-rce: CVE-2026-100886 | effortless rce on the seetong ts81xxd3x (iDVR 9000 platform). This has only been tested on emulated firmware, as I don't own a seetong nvr, as so, you should only try this on devices you own. · GitHubSecondarySeetong recorders reportedly permit unauthenticated remote full device control