PT-2025-27538 · Avtech · Avtech Dvr
Gergely Eberhardt
·
Published
2025-07-01
·
Updated
2026-06-03
·
CVE-2025-34054
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions:
AVTECH DVR devices (affected versions not specified)
Description:
An unauthenticated command injection issue exists in AVTECH DVR devices. This is due to the lack of input sanitization when using
wget in the "Search.cgi?action=cgi query" endpoint, allowing attackers to inject shell commands through the username or queryb64str parameters. As a result, commands can be executed with root privileges.Recommendations:
For all affected versions, consider disabling access to the "Search.cgi?action=cgi query" endpoint until a patch is available.
Restrict the use of the
wget command without proper input sanitization to minimize the risk of exploitation.
Avoid using the username and queryb64str parameters in the affected API endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avtech Dvr