← back
CVE-2025-34053

AVTECH IP camera, DVR, and NVR Devices Authentication Bypass via .cab Path Manipulation

CVSS 6.9 MEDIUMEPSS 0.5%CWE-290
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
01 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →