216.73.217.22

CVE-2025-34055

· Published 01/07/2025 15:15 · Modified 01/07/2025 15:15

Labels: CVE-2025-34055 2025-07-01CVE-2025-34055CWE-20[email protected]

Essential information

Published
01/07/2025 15:15
Modified
01/07/2025 15:15
Author
Creator
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the ActionD daemon. Authenticated users can invoke the DoShellCmd operation, passing arbitrary input via the strCmd parameter. This input is executed directly by the system shell without sanitation allowing attackers to execute commands as the root user.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
avtech / avtech dvr cpe:2.3:a:avtech:avtech_dvr:*:*:*:*:*:*:*:*
avtech / avtech nvr cpe:2.3:a:avtech:avtech_nvr:*:*:*:*:*:*:*:*
avtech / avtech ip camera cpe:2.3:a:avtech:avtech_ip_camera:*:*:*:*:*:*:*:*

References