PT-2025-27540 · Avtech · Avtech Dvr+2

Gergely Eberhardt

·

Published

2025-07-01

·

Updated

2025-07-04

·

CVE-2025-34056

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: AVTECH IP camera, DVR, and NVR devices (affected versions not specified)
Description: An OS command injection issue exists in the devices via the "PwdGrp.cgi" endpoint, which handles user and group management operations. Authenticated users can supply input through the pwd or grp parameters, which are directly embedded into system commands without proper sanitation. This allows for the execution of arbitrary shell commands with root privileges.
Recommendations: As a temporary workaround, consider disabling access to the "PwdGrp.cgi" endpoint until a patch is available. Restrict access to the pwd and grp parameters in the affected endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-11525
CVE-2025-34056

Affected Products

Avtech Dvr
Avtech Ip Cameras
Avtech Nvr