CVE-2025-34053

MEDIUM

AVTECH IP camera, DVR, and NVR devices - Authentication Bypass via .cab URL Spoofing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-34053. PoCs published by Gergely Eberhardt.

AI-analyzed exploit summary This is a detailed writeup describing multiple vulnerabilities in Avtech devices, including unauthenticated command injection, authentication bypasses, and information disclosure. It provides proof-of-concept URLs and explanations for each vulnerability but does not contain executable exploit code.

Description

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.

Exploits (1)

exploitdb WRITEUP
by Gergely Eberhardt · pythonwebappscgi
https://www.exploit-db.com/exploits/40500

This is a detailed writeup describing multiple vulnerabilities in Avtech devices, including unauthenticated command injection, authentication bypasses, and information disclosure. It provides proof-of-concept URLs and explanations for each vulnerability but does not contain executable exploit code.

Classification
Writeup 100%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Avtech IP cameras, NVRs, DVRs (all firmware versions)
No auth needed
Prerequisites: Network access to the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5

Scores

CVSS v4 6.9
EPSS 0.0055
EPSS Percentile 41.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (50)
AVTECH/IP camera, DVR, and NVR devices 1000-1000-1000-1000
AVTECH/IP camera, DVR, and NVR devices 1000C-1000C-1000C-1000C
AVTECH/IP camera, DVR, and NVR devices 1001-1000-1000-1000
AVTECH/IP camera, DVR, and NVR devices 1001-1001-1000-1000
AVTECH/IP camera, DVR, and NVR devices 1002-1000-1000-1000
AVTECH/IP camera, DVR, and NVR devices 1002-1002-1000-1002
AVTECH/IP camera, DVR, and NVR devices 1002D-1000D-1000D-1000D
AVTECH/IP camera, DVR, and NVR devices 1003-1000-1000-1001
AVTECH/IP camera, DVR, and NVR devices 1003-1001-1001-1000
AVTECH/IP camera, DVR, and NVR devices 1003-1002-1001-1000
... and 40 more
Published Jul 01, 2025
Tracked Since Feb 18, 2026