CVE-2025-34054

High PUBLISHED

AVTECH IP camera, DVR, and NVR Devices Unauthenticated Command Injection

AVTECH · IP camera, DVR, and NVR Devices

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
10.0 Critical

At a Glance

An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-04 UTC.

CVE Published
Jul 01, 2025
Exploitation Reported
Mar 23, 2026
CVSS
10.0 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
AVTECH
IP camera, DVR, and NVR Devices

1008-1002-1005-1000

Affected
AVTECH
IP camera, DVR, and NVR Devices

1009-1003-1006-1001

Affected
AVTECH
IP camera, DVR, and NVR Devices

1009Y-1003Y-1006Y-1001Y

Affected
AVTECH
IP camera, DVR, and NVR Devices

1010-1004-1007-1001

Affected
AVTECH
IP camera, DVR, and NVR Devices

1011-1005-1008-1002

Affected
AVTECH
IP camera, DVR, and NVR Devices

1014-1005-1009-1002

Affected
AVTECH
IP camera, DVR, and NVR Devices

1015-1006-1010-1003

Affected
AVTECH
IP camera, DVR, and NVR Devices

1016-1007-1011-1003

Affected
AVTECH
IP camera, DVR, and NVR Devices

1017-1008-1012-1002

Affected
AVTECH
IP camera, DVR, and NVR Devices

1017Y-1008Y-1012Y-1002Y

Affected
AVTECH
IP camera, DVR, and NVR Devices

1018-1008-1012-1004

Affected
AVTECH
IP camera, DVR, and NVR Devices

1019-1009-1013-1003

Affected
AVTECH
IP camera, DVR, and NVR Devices

1019c-1012c-1014c-1001c-FFFF

Affected
AVTECH
IP camera, DVR, and NVR Devices

1022-1014-1016-1002-FFFF

Affected
AVTECH
IP camera, DVR, and NVR Devices

1022Y-1014Y-1016Y-1002Y-FFFF

Affected
AVTECH
IP camera, DVR, and NVR Devices

1023-1014-1017-1002-FFFF

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.