Information Disclosure Vulnerability in AVTECH IP Cameras, DVRs, and NVRs
CVE-2025-34052
6.9MEDIUM
What is CVE-2025-34052?
An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and NVRs that allows attackers to access sensitive internal device information. This vulnerability is exploited through the Machine.cgi?action=get_capability endpoint, which reveals critical details such as firmware version, MAC address, and codec support. As these devices do not require authentication for access, unauthorized users can potentially leverage this information for malicious intent.
Affected Version(s)
DVR devices 0
IP cameras 0
NVR devices 0
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Gergely Eberhardt (SEARCH-LAB.hu)