Information Disclosure Vulnerability in AVTECH IP Cameras, DVRs, and NVRs
CVE-2025-34052

6.9MEDIUM

Key Information:

Vendor

Avtech

Vendor
CVE Published:
1 July 2025

Badges

👾 Exploit Exists

What is CVE-2025-34052?

An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and NVRs that allows attackers to access sensitive internal device information. This vulnerability is exploited through the Machine.cgi?action=get_capability endpoint, which reveals critical details such as firmware version, MAC address, and codec support. As these devices do not require authentication for access, unauthorized users can potentially leverage this information for malicious intent.

Affected Version(s)

DVR devices 0

IP cameras 0

NVR devices 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gergely Eberhardt (SEARCH-LAB.hu)
.