Description
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-04 UTC.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
1008-1002-1005-1000
1009-1003-1006-1001
1009Y-1003Y-1006Y-1001Y
1010-1004-1007-1001
1011-1005-1008-1002
1014-1005-1009-1002
1015-1006-1010-1003
1016-1007-1011-1003
1017-1008-1012-1002
1017Y-1008Y-1012Y-1002Y
1018-1008-1012-1004
1019-1009-1013-1003
1019c-1012c-1014c-1001c-FFFF
1022-1014-1016-1002-FFFF
1022Y-1014Y-1016Y-1002Y-FFFF
1023-1014-1017-1002-FFFF
Credits
Gergely Eberhardt (SEARCH-LAB.hu)
References
www.exploit-db.com/exploits/40500
avtech.com/
web.archive.org/...6-AVTech-devices-multiple-vulnerabilities
web.archive.org/...1029201749/https://github.com/ebux/AVTECH
vulncheck.com/...ries/avtech-ipcamera-nvr-dvr-mulitple-vulns