An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints. | |
Title | AVTECH IP camera, DVR, and NVR Devices Authentication Bypass via .cab Path Manipulation | |
Weaknesses | CWE-290 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-01T14:45:02.858Z
Updated: 2025-07-01T18:46:09.474Z
Reserved: 2025-04-15T19:15:22.548Z
Link: CVE-2025-34053

Updated: 2025-07-01T18:30:50.237Z

Status : Awaiting Analysis
Published: 2025-07-01T15:15:23.760
Modified: 2025-07-03T15:14:12.767
Link: CVE-2025-34053

No data.