An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and NVRs via Machine.cgi?action=get_capability. Sensitive internal device information such as firmware version, MAC address, and codec support can be accessed without authentication.
History

Tue, 01 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Jul 2025 15:00:00 +0000

Type Values Removed Values Added
Description An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and NVRs via Machine.cgi?action=get_capability. Sensitive internal device information such as firmware version, MAC address, and codec support can be accessed without authentication.
Title AVTECH IP camera, DVR, and NVR Devices Unauthenticated Information Disclosure
Weaknesses CWE-200
CWE-306
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-07-01T14:44:40.785Z

Updated: 2025-07-01T18:45:37.735Z

Reserved: 2025-04-15T19:15:22.548Z

Link: CVE-2025-34052

cve-icon Vulnrichment

Updated: 2025-07-01T18:30:02.508Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-01T15:15:23.623

Modified: 2025-07-03T15:14:12.767

Link: CVE-2025-34052

cve-icon Redhat

No data.