AVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution
Vulnerability Description
An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group management operations. Authenticated users can supply input through the pwd or grp parameters, which are directly embedded into system commands without proper sanitation. This allows for the execution of arbitrary shell commands with root privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34056
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Gergely Eberhardt (SEARCH-LAB.hu)
References
- https://www.exploit-db.com/exploits/40500
- https://avtech.com/
- https://web.archive.org/web/20240810225729/https://www.search-lab.hu/advisories/126-AVTech-devices-multiple-vulnerabilities
- https://web.archive.org/web/20161029201749/https://github.com/ebux/AVTECH
- https://vulncheck.com/advisories/avtech-ipcamera-nvr-dvr-mulitple-vulns
More from AVTECH
View All →Affected Vendor
AVTECH
View all reports →