CVE-2025-34054: Avtech IP Camera, Dvr, And NVR Devices
Critical severity, CVSS 10.0. EPSS: 2.7% chance of exploitation in the next 30 days.
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-04 UTC.
Affected products
- Avtech IP Camera, Dvr, And NVR Devices: version 1008-1002-1005-1000 only; version 1009-1003-1006-1001 only; version 1009Y-1003Y-1006Y-1001Y only; version 1010-1004-1007-1001 only; version 1011-1005-1008-1002 only; version 1014-1005-1009-1002 only; …
Published 2025-07-01. Last modified 2026-06-17.