← back
CVE-2025-34054criticalobserved exploitationCWE-78

AVTECH IP camera, DVR, and NVR Devices Unauthenticated Command Injection

70Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 10epss 2.7%
from disclosure to weapon
Published on NVDJul 1
VulnCheckOct 22
exploitation probability
2.7%top 15% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-04 UTC.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.