Back to overview

CVE-2025-34054

CRITICAL Exploitation: PoC
10.0
CVSS 4.0
Description
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-04 UTC.

Metadata

CVE ID
CVE-2025-34054
State
PUBLISHED
Assigner
VulnCheck
Reserved
2025-04-15 19:15 UTC
Published
2025-07-01 14:46 UTC
Last updated
2026-04-07 14:09 UTC
Primary CWE
CWE-78
CWE-78 Improper Neutralization of Special Elements used in a…
Vendor / Product
AVTECH / IP camera, DVR, and NVR Devices
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
AVTECH IP camera, DVR, and NVR Devices 1008-1002-1005-1000, 1009-1003-1006-1001, 1009Y-1003Y-1006Y-1001Y, 1010-1004-1007-1001 …
Weakness (CWE)
CWESourceDescription
CWE-78 cna CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Back to overview