Description
An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.
Problem types
CWE-295 Improper Certificate Validation
Product status
Any version
Any version
Any version
Credits
Gergely Eberhardt (SEARCH-LAB.hu)
References
www.exploit-db.com/exploits/40500
avtech.com/
web.archive.org/...6-AVTech-devices-multiple-vulnerabilities
web.archive.org/...1029201749/https://github.com/ebux/AVTECH
vulncheck.com/...ries/avtech-ipcamera-nvr-dvr-mulitple-vulns