CVE-2025-34053: Avtech IP Camera, Dvr, And NVR Devices

Medium severity, CVSS 6.9. EPSS: 0.6% chance of exploitation in the next 30 days.

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.

Affected products

  • Avtech IP Camera, Dvr, And NVR Devices: version 1000-1000-1000-1000 only; version 1000C-1000C-1000C-1000C only; version 1001-1000-1000-1000 only; version 1001-1001-1000-1000 only; version 1002-1000-1000-1000 only; version 1002-1002-1000-1002 only; …

Published 2025-07-01. Last modified 2026-06-17.