CNNVD-202507-050 Information

CNNVD ID

CNNVD-202507-050

CVE-2025-34056

  • CNNVD Published: 2025-07-01

Description (Chinese)

AVTECH IP camera等都是美国AVTECH公司的产品。AVTECH IP camera是一系列网络安全摄像头。AVTECH DVR是一款数位录影主机。AVTECH NVR是一款网络录像机。 AVTECH IP camera、AVTECH DVR和AVTECH NVR存在安全漏洞,该漏洞源于PwdGrp.cgi端点未清理输入导致OS命令注入。

Description (English)

AVTECH IP camera and others are products of AVTECH in the United States. AVTECCH IP camera is a series of network security cameras. AVTECCH DVD is a digital video host. AVTECCH NVR is a web-based video recorder. AVTECH IP Camera, AVTECH DVR and AVTECH NVR had a security loophole, which originated from the failure of the PwdGrp.cgi endpoint to clean up input leading to OS command injection.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

陞泰科技

Published

2025-07-01

Last Modified

2026-02-24

References

https://www.exploit-db.com/exploits/40500 https://vulncheck.com/advisories/avtech-ipcamera-nvr-dvr-mulitple-vulns https://avtech.com/ https://www.search-lab.hu/advisories/126-AVTech-devices-multiple-vulnerabilities https://web.archive.org/web/20240810225729/ https://github.com/ebux/AVTECH https://web.archive.org/web/20161029201749/ https://access.redhat.com/security/cve/cve-2025-34056

Patch

https://web.archive.org/

Share on: