CVE-2025-34054 Details
Description
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-04 UTC.
A command injection vulnerability has been identified in AVTECH DVR devices. This vulnerability allows unauthenticated attackers to execute arbitrary shell commands with root privileges. The issue arises in the Search.cgi component, specifically through the cgi_query action, which is vulnerable due to improper input sanitization. Exploitation can be achieved by injecting commands through the username or queryb64str parameters.
Users are advised to change the default admin password and avoid exposing the device's web interface to the internet.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 1, 2025CISA-ADP
Assessed Jul 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://avtech.com/ | [email protected] | Vendor |
| https://vulncheck.com/advisories/avtech-ipcamera-nvr-dvr-mulitple-vulns | [email protected] | AdvisoryBundleExploit |
| https://web.archive.org/web/20161029201749/https://github.com/ebux/AVTECH | [email protected] | BundleExploitTechnical Analysis |
| https://web.archive.org/web/20240810225729/https://www.search-lab.hu/advisories/126-AVTech-devices-multiple-vulnerabilities | [email protected] | AdvisoryBundleRemedy |
| https://www.exploit-db.com/exploits/40500 | [email protected] | Exploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AVTECH IP Camera | All versions |
CPE
Remediation
| |
| AVTECH NVR | All versions |
CPE
Remediation
| |
| AVTECH DVR | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 20, 2025 | CVE Modified | [email protected] |
| Nov 17, 2025 | CVE Modified | [email protected] |
| Nov 17, 2025 | CVE Modified | [email protected] |
| Jul 1, 2025 | New CVE Received | [email protected] |
Volerion