Authentication Bypass in AVTECH IP Camera, DVR, and NVR Devices
CVE-2025-34065
What is CVE-2025-34065?
An authentication bypass vulnerability has been identified in the streamd web server of AVTECH IP camera, DVR, and NVR devices. This issue allows unauthorized access to any request containing the string '/nobody' in the URL, effectively circumventing the standard login authentication mechanisms. This vulnerability poses a significant risk to device security, enabling potential attackers to access device functionalities without authentication.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
IP camera, DVR, and NVR Devices 1000-1000-1000-1000
IP camera, DVR, and NVR Devices 1000C-1000C-1000C-1000C
IP camera, DVR, and NVR Devices 1001-1000-1000-1000
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
