Server-Side Request Forgery Vulnerability in AVTECH DVR Devices
CVE-2025-34051
What is CVE-2025-34051?
A significant vulnerability has been identified in various firmware versions of AVTECH DVR devices, specifically concerning the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint. This exposure, which requires no authentication, allows attackers to manipulate parameters such as ip, port, and queryb64str. As a result, attackers could potentially execute arbitrary HTTP requests from the DVR to both internal and external systems, leading to the possible exposure of sensitive information or unauthorized interactions with internal services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DVR devices 1001-1000-1000-1000
DVR devices 1001-1000-1001-1001
DVR devices 1002-1000-1002-1001
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
