CVE-2025-34051: AVTECH DVR Devices Server-Side Request Forgery
A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgiquery endpoint without authentication. An attacker can manipulate the ip, port, and queryb64str parameters to make arbitrary HTTP requests from the DVR to internal or external systems, potentially exposing sensitive data or interacting with internal services.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34051?
CVE-2025-34051 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2025-34051?
To fix CVE-2025-34051, update the firmware of the AVTECH DVR devices to the latest version provided by the vendor.
What are the potential impacts of CVE-2025-34051?
The potential impacts of CVE-2025-34051 include the ability for an attacker to perform unauthorized server-side requests and access sensitive information.
Which devices are affected by CVE-2025-34051?
CVE-2025-34051 affects multiple firmware versions of AVTECH DVR devices.
Is authentication required to exploit CVE-2025-34051?
No, CVE-2025-34051 can be exploited without authentication, making it particularly dangerous.