CVE-2025-34054: AVTECH IP camera, DVR, and NVR Devices Unauthenticated Command Injection
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgiquery. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-04 UTC.
Other sources
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgiquery. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-03-07 UTC.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34054?
CVE-2025-34054 is considered a critical vulnerability due to its ability to allow unauthenticated command injection on AVTECH DVR devices.
How do I fix CVE-2025-34054?
To fix CVE-2025-34054, ensure that your AVTECH DVR firmware is updated to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-34054?
CVE-2025-34054 affects users of AVTECH DVR devices that are vulnerable to command injection via the Search.cgi endpoint.
What are the consequences of exploiting CVE-2025-34054?
Exploiting CVE-2025-34054 can allow attackers to execute arbitrary commands with root privileges on the affected AVTECH DVR device.
What mitigation strategies can be implemented for CVE-2025-34054?
Mitigation strategies for CVE-2025-34054 include network segmentation, reducing internet exposure, and implementing strict access controls.