CVE-2025-34052
AVTECH IP camera, DVR, and NVR Devices Unauthenticated Information Disclosure
Severity Score
6.9
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and NVRs via Machine.cgi?action=get_capability. Sensitive internal device information such as firmware version, MAC address, and codec support can be accessed without authentication.
Existe una vulnerabilidad de divulgación de información no autenticada en AVTECH IP cameras, DVRs, y NVRs mediante Machine.cgi?action=get_capability. Se puede acceder sin autenticación a información confidencial interna del dispositivo, como la versión del firmware, la dirección MAC y la compatibilidad de códecs.
*Credits:
Gergely Eberhardt (SEARCH-LAB.hu)
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2025-04-15 CVE Reserved
- 2025-07-01 CVE Published
- 2025-07-01 CVE Updated
- 2025-07-01 First Exploit
- 2025-07-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-306: Missing Authentication for Critical Function
CAPEC
- CAPEC-224: Fingerprinting
References (5)
URL | Tag | Source |
---|---|---|
https://avtech.com | Product | |
https://vulncheck.com/advisories/avtech-ipcamera-nvr-dvr-mulitple-vulns | Third Party Advisory | |
https://web.archive.org/web/20240810225729/https://www.search-lab.hu/advisories/126-AVTech-devices-multiple-vulnerabilities | Technical Description |
URL | Date | SRC |
---|---|---|
https://web.archive.org/web/20161029201749/https://github.com/ebux/AVTECH | 2025-07-01 | |
https://www.exploit-db.com/exploits/40500 | 2025-07-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
AVTECH Search vendor "AVTECH" | IP Cameras Search vendor "AVTECH" for product "IP Cameras" | 0 Search vendor "AVTECH" for product "IP Cameras" and version "0" | en |
Affected
| ||||||
AVTECH Search vendor "AVTECH" | DVR Devices Search vendor "AVTECH" for product "DVR Devices" | 0 Search vendor "AVTECH" for product "DVR Devices" and version "0" | en |
Affected
| ||||||
AVTECH Search vendor "AVTECH" | NVR Devices Search vendor "AVTECH" for product "NVR Devices" | 0 Search vendor "AVTECH" for product "NVR Devices" and version "0" | en |
Affected
|