CVE Database
/

CVE-2025-34066

Back to search

CVE-2025-34066

Published: Jul 1, 2025

Modified: Apr 7, 2026

PUBLISHED

Description

An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.

VendorProductVersions

AVTECH

IP cameras

affected
0

AVTECH

DVR devices

affected
0

AVTECH

NVR devices

affected
0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now