A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user interaction.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user interaction. | |
Title | AVTECH IP Camera, DVR, and NVR Devices Cross-Site Request Forgery | |
Weaknesses | CWE-352 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-01T14:42:57.143Z
Updated: 2025-07-01T18:45:06.703Z
Reserved: 2025-04-15T19:15:22.548Z
Link: CVE-2025-34050

Updated: 2025-07-01T18:29:18.916Z

Status : Awaiting Analysis
Published: 2025-07-01T15:15:22.933
Modified: 2025-07-03T15:14:12.767
Link: CVE-2025-34050

No data.