CVE-2016-15047 Details
Description
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can supply crafted input to execute arbitrary system commands as root. Successful exploitation grants full control of the device, and - depending on deployment and whether the device stores credentials or has network reachability to internal systems - may enable credential theft, lateral movement, or data exfiltration. The archived SEARCH-LAB disclosure implies that this vulnerability was remediated in early 2017, but AVTECH has not defined an affected version range.
A vulnerability allowing authenticated OS command injection has been identified in AVTECH devices that include the CloudSetup.cgi management endpoint. The issue arises because the 'exefile' parameter in CloudSetup.cgi is passed to the system command execution without proper validation or whitelisting. An authenticated attacker who can access this endpoint can execute arbitrary system commands as root. Successful exploitation provides full control of the device and, depending on the device's deployment and network reachability, may lead to credential theft, lateral movement, or data exfiltration.
AVTECH has released firmware updates for affected devices. Users are advised to change the default admin password and operate devices behind a firewall.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 9, 2025CISA-ADP
Assessed Oct 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AVTECH IP Camera | All versions |
CPE
Remediation
| |
| AVTECH NVR | All versions |
CPE
Remediation
| |
| AVTECH DVR | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 9, 2025 | CVE Modified | [email protected] |
| Oct 9, 2025 | New CVE Received | [email protected] |
Volerion