An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group management operations. Authenticated users can supply input through the pwd or grp parameters, which are directly embedded into system commands without proper sanitation. This allows for the execution of arbitrary shell commands with root privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group management operations. Authenticated users can supply input through the pwd or grp parameters, which are directly embedded into system commands without proper sanitation. This allows for the execution of arbitrary shell commands with root privileges. | |
Title | AVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution | |
Weaknesses | CWE-20 CWE-78 |
|
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-01T14:46:52.800Z
Updated: 2025-07-01T18:34:41.482Z
Reserved: 2025-04-15T19:15:22.549Z
Link: CVE-2025-34056

Updated: 2025-07-01T18:34:35.332Z

Status : Awaiting Analysis
Published: 2025-07-01T15:15:24.203
Modified: 2025-07-03T15:14:12.767
Link: CVE-2025-34056

No data.