A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication. An attacker can manipulate the ip, port, and queryb64str parameters to make arbitrary HTTP requests from the DVR to internal or external systems, potentially exposing sensitive data or interacting with internal services.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication. An attacker can manipulate the ip, port, and queryb64str parameters to make arbitrary HTTP requests from the DVR to internal or external systems, potentially exposing sensitive data or interacting with internal services. | |
Title | AVTECH DVR Devices Server-Side Request Forgery | |
Weaknesses | CWE-200 CWE-918 |
|
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-01T14:44:22.913Z
Updated: 2025-07-01T14:59:04.311Z
Reserved: 2025-04-15T19:15:22.548Z
Link: CVE-2025-34051

Updated: 2025-07-01T14:54:53.451Z

Status : Awaiting Analysis
Published: 2025-07-01T15:15:23.467
Modified: 2025-07-03T15:14:12.767
Link: CVE-2025-34051

No data.