CVE-2025-34054
critical · 10An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-04 UTC.
10
CVSS
2.7%
EPSS (exploit prob.)
85th
EPSS percentile
2025-07-01
Published
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weaknesses
CWE-78
References
- https://avtech.com/
- https://vulncheck.com/advisories/avtech-ipcamera-nvr-dvr-mulitple-vulns
- https://web.archive.org/web/20161029201749/https://github.com/ebux/AVTECH
- https://web.archive.org/web/20240810225729/https://www.search-lab.hu/advisories/126-AVTech-devices-multiple-vulnerabilities
- https://www.exploit-db.com/exploits/40500
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-34054