CVE-2025-34051: Avtech Dvr Devices

Medium severity, CVSS 6.9. EPSS: 0.6% chance of exploitation in the next 30 days.

A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication. An attacker can manipulate the ip, port, and queryb64str parameters to make arbitrary HTTP requests from the DVR to internal or external systems, potentially exposing sensitive data or interacting with internal services.

Affected products

  • Avtech Dvr Devices: version 1001-1000-1000-1000 only; version 1001-1000-1001-1001 only; version 1002-1000-1002-1001 only; version 1002-1001-1001-1001 only; version 1004-1002-1001-1000 only; version 1004-1002-1003-1000-FFFF only; …

Published 2025-07-01. Last modified 2026-06-17.