JPCERT flags vulnerable DVR/NVR scanning traffic
JPCERT's TSUBAME sensors observed Telnet scanning traffic largely originating from outdated, unpatched DVR/NVR devices in Q4 2025.
JPCERT/CC's TSUBAME Report Overflow for October-December 2025 examines monitoring trends from its global sensor network, focusing on Telnet (23/TCP) traffic originating from Japan. Analysts observed a spike in October followed by a decline from early November, but noted that a large share of this traffic—up to 80% on some days—came from specific groups of DVR/NVR devices. Login banners on these devices showed outdated copyright dates (e.g., 2014), indicating long-neglected firmware that likely contains known, exploitable vulnerabilities.
The report also compared packet volumes between domestic and overseas sensors, finding overseas sensors consistently receive more traffic, with a gradual upward trend in both regions from October onward. Common destination ports (22, 23, 80, 443, 8080/TCP) were observed across nearly all sensors regardless of region, indicating widespread, non-targeted scanning activity against these standard service ports.
No specific alerts or novel threats were issued this quarter; the report is primarily informational, reinforcing the value of distributed monitoring and urging owners of DVR/NVR devices to verify firmware update status given the persistence of internet-facing, outdated devices.
Source reporting: https://blogs.jpcert.or.jp/en/2026/05/tsubame_overflow_2025-10-12.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free