CVE-2025-34050 Details
Description
A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user interaction.
A cross-site request forgery (CSRF) vulnerability has been identified in the web interface of AVTECH IP cameras, DVRs, and NVRs. This vulnerability allows attackers to send malicious requests that, when executed in the context of an authenticated user's browser session, can make unauthorized changes to the device's configuration without any user interaction. The vulnerability exists because the web interface lacks proper CSRF protection, enabling attackers to exploit valid user sessions or, in some cases, default admin credentials.
Users are advised to change the default admin password and avoid exposing the web interface to the internet. AVTECH has released firmware updates for some vulnerabilities, but it's unclear if this specific issue has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 1, 2025CISA-ADP
Assessed Jul 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://avtech.com/ | [email protected] | Vendor |
| https://vulncheck.com/advisories/avtech-ipcamera-nvr-dvr-mulitple-vulns | [email protected] | AdvisoryBundleExploitRemedy |
| https://web.archive.org/web/20161029201749/https://github.com/ebux/AVTECH | [email protected] | BundleExploitTechnical Analysis |
| https://web.archive.org/web/20240810225729/https://www.search-lab.hu/advisories/126-AVTech-devices-multiple-vulnerabilities | [email protected] | AdvisoryBundleRemedy |
| https://www.exploit-db.com/exploits/40500 | [email protected] | Exploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AVTECH IP Camera | All versions |
CPE
Remediation
| |
| AVTECH DVR | All versions |
CPE
Remediation
| |
| AVTECH NVR | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2025 | New CVE Received | [email protected] |
Volerion