CVE-2025-34050: AVTECH IP Camera, DVR, and NVR Devices Cross-Site Request Forgery
A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34050?
CVE-2025-34050 is classified as a critical vulnerability due to its potential to allow unauthorized changes to AVTECH devices.
How do I fix CVE-2025-34050?
To mitigate CVE-2025-34050, users should implement access controls and ensure that their AVTECH devices firmware is up to date.
What devices are affected by CVE-2025-34050?
CVE-2025-34050 affects AVTECH IP cameras, DVR, and NVR devices.
What type of attack is CVE-2025-34050 associated with?
CVE-2025-34050 is associated with cross-site request forgery (CSRF) attacks.
Can CVE-2025-34050 be exploited remotely?
Yes, CVE-2025-34050 can be exploited remotely as it allows attackers to execute malicious requests within an authenticated user's session.