CVE-2025-34055

CRITICAL

AVTECH DVR-NVR-IP Camera - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-34055. PoCs published by Gergely Eberhardt.

AI-analyzed exploit summary This is a detailed writeup describing multiple vulnerabilities in Avtech devices, including unauthenticated command injection, authentication bypasses, and information disclosure. It provides proof-of-concept URLs and explanations for each vulnerability but does not contain executable exploit code.

Description

An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the ActionD daemon. Authenticated users can invoke the DoShellCmd operation, passing arbitrary input via the strCmd parameter. This input is executed directly by the system shell without sanitation allowing attackers to execute commands as the root user.

Exploits (1)

exploitdb WRITEUP
by Gergely Eberhardt · pythonwebappscgi
https://www.exploit-db.com/exploits/40500

This is a detailed writeup describing multiple vulnerabilities in Avtech devices, including unauthenticated command injection, authentication bypasses, and information disclosure. It provides proof-of-concept URLs and explanations for each vulnerability but does not contain executable exploit code.

Classification
Writeup 100%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Avtech IP cameras, NVRs, DVRs (all firmware versions)
No auth needed
Prerequisites: Network access to the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5

Scores

CVSS v4 9.4
EPSS 0.0153
EPSS Percentile 71.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-20 CWE-78
Status published
Products (50)
AVTECH/IP camera, DVR, and NVR Devices 1001-1000-1000-1000
AVTECH/IP camera, DVR, and NVR Devices 1002-1000-1000-1000
AVTECH/IP camera, DVR, and NVR Devices 1002-1001-1001-1001
AVTECH/IP camera, DVR, and NVR Devices 1003-1000-1001-1000
AVTECH/IP camera, DVR, and NVR Devices 1003-1001-1001-1000
AVTECH/IP camera, DVR, and NVR Devices 1003-1001-1001-1001
AVTECH/IP camera, DVR, and NVR Devices 1004-1000-1000-1000
AVTECH/IP camera, DVR, and NVR Devices 1004-1001-1001-1001
AVTECH/IP camera, DVR, and NVR Devices 1004-1001-1002-1000
AVTECH/IP camera, DVR, and NVR Devices 1004-1002-1001-1000
... and 40 more
Published Jul 01, 2025
Tracked Since Feb 18, 2026