Information Disclosure Vulnerability in AVTECH IP Cameras, DVRs, and NVRs
CVE-2025-34052
What is CVE-2025-34052?
An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and NVRs that allows attackers to access sensitive internal device information. This vulnerability is exploited through the Machine.cgi?action=get_capability endpoint, which reveals critical details such as firmware version, MAC address, and codec support. As these devices do not require authentication for access, unauthorized users can potentially leverage this information for malicious intent.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DVR devices 0
IP cameras 0
NVR devices 0
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
