CVE Database
/

CVE-2025-34051

Back to search

CVE-2025-34051

Published: Jul 1, 2025

Modified: Apr 7, 2026

PUBLISHED

Description

A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication. An attacker can manipulate the ip, port, and queryb64str parameters to make arbitrary HTTP requests from the DVR to internal or external systems, potentially exposing sensitive data or interacting with internal services.

VendorProductVersions

AVTECH

DVR devices

affected
1001-1000-1000-1000
affected
1001-1000-1001-1001
affected
1002-1000-1002-1001
unaffected
1002-1001-1000-1000
affected
1002-1001-1001-1001

+67 more versions

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now