PT-2024-5360 · Avtech · Avtech Ip Cameras+1

Aline Eliovich

+1

·

Published

2024-08-01

·

Updated

2025-10-10

·

CVE-2024-7029

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AVTECH AVM1203 versions prior to the latest supported version AVTECH IP cameras (affected versions not specified)
Description The issue is related to a command injection vulnerability found in the brightness function of AVTECH closed-circuit television (CCTV) cameras, allowing for remote code execution (RCE) without authentication. This vulnerability has been exploited by the Mirai botnet to spread malware. Approximately 4,386,526 potentially vulnerable devices have been identified. The vulnerability has been actively exploited since at least 2019, but it wasn’t formally recognized until August 2024.
Recommendations For AVTECH AVM1203 versions prior to the latest supported version: Consider replacing the device with a newer model that receives regular security updates. For AVTECH IP cameras (affected versions not specified): Update the firmware to the latest version, if available, and ensure that all devices are properly configured and secured to prevent exploitation. As a temporary workaround, consider disabling the brightness function or restricting access to the camera's network interface until a patch is available.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-05993
CVE-2024-7029

Affected Products

Avtech Avm1203
Avtech Ip Cameras