PT-2025-27538 · Avtech · Avtech Dvr

·

CVE-2025-34054

·

Published

2025-07-01

·

Updated

2026-06-04

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions AVTECH DVR (affected versions not specified)
Description An unauthenticated command injection issue exists in AVTECH DVR devices. The vulnerability occurs because the wget utility is used without proper input sanitization in the 'Search.cgi?action=cgi query' endpoint. This allows remote attackers to inject shell commands through the username or queryb64str parameters, resulting in the execution of arbitrary code with root privileges. Real-world exploitation of this issue was observed by the Shadowserver Foundation on 2025-03-07 UTC.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11528
CVE-2025-34054

Affected Products

Avtech Dvr