CVE-2025-34066: AVTECH IP camera, DVR, and NVR Devices Unauthenticated Information Disclosure
Published Jul 1, 2025
·Updated
An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.
Affected Software
3 affected components
AVTECH IP camera
AVTECH DVR
AVTECH NVR
Event History
Jul 1, 2025
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-34066?
CVE-2025-34066 is a medium severity vulnerability that can lead to man-in-the-middle (MITM) attacks.
2
How do I fix CVE-2025-34066?
To mitigate CVE-2025-34066, ensure that any scripts do not use wget with the --no-check-certificate option.
3
Which devices are affected by CVE-2025-34066?
CVE-2025-34066 affects AVTECH IP cameras, DVRs, and NVRs.
4
What type of attack is possible due to CVE-2025-34066?
CVE-2025-34066 allows for man-in-the-middle (MITM) attacks during HTTPS communications.
5
What causes CVE-2025-34066?
CVE-2025-34066 is caused by improper certificate validation in scripts used by AVTECH devices.