CVE-2025-34065

AVTECH - Auth Bypass

Title source: llm

Description

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.

Exploits (1)

exploitdb WRITEUP
by Gergely Eberhardt · pythonwebappscgi
https://www.exploit-db.com/exploits/40500

Scores

EPSS 0.0012
EPSS Percentile 30.6%

Classification

CWE
CWE-290
Status draft

Timeline

Published Jul 01, 2025
Tracked Since Feb 18, 2026