PT-2025-27537 · Avtech · Avtech Dvr+2

Gergely Eberhardt

·

Published

2025-07-01

·

Updated

2025-07-01

·

CVE-2025-34053

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: AVTECH IP camera, DVR, and NVR devices (affected versions not specified)
Description: An authentication bypass issue exists in the streamd web server of AVTECH devices. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-34053

Affected Products

Avtech Dvr
Avtech Ip Cameras
Avtech Nvr