CVE-2025-34065: AVTECH IP camera, DVR, and NVR Devices Authentication Bypass via /nobody URL Path
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34065?
CVE-2025-34065 is classified as a critical severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2025-34065?
To mitigate CVE-2025-34065, update the firmware of AVTECH devices to the latest version provided by the manufacturer.
What devices are affected by CVE-2025-34065?
CVE-2025-34065 affects AVTECH IP cameras, DVRs, and NVRs with vulnerable streamd web server functionalities.
What type of attack does CVE-2025-34065 enable?
CVE-2025-34065 enables unauthenticated access to sensitive information through URL manipulation containing "/nobody".
Can CVE-2025-34065 lead to further exploitation?
Yes, CVE-2025-34065 can potentially lead to further exploitation of vulnerable devices if not promptly addressed.