NA - CVE-2025-34050 - A cross-site request forgery (CSRF)...
A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context...
NA - CVE-2025-34051 - A server-side request forgery vulnerability...
A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication....
NA - CVE-2025-34052 - An unauthenticated information disclosure...
An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and NVRs via Machine.cgi?action=get_capability. Sensitive internal device information such as firmware...
NA - CVE-2025-34053 - An authentication bypass vulnerability exists...
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing...
NA - CVE-2025-34054 - An unauthenticated command injection...
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands...
NA - CVE-2025-34055 - An OS command injection vulnerability exists in...
An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the ActionD daemon. Authenticated users can invoke...
NA - CVE-2025-34056 - An OS command injection vulnerability exists in...
An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group management operations. Authenticated users can...
NA - CVE-2025-34058 - Hikvision Streaming Media Management Server...
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After authenticating with these...
NA - CVE-2025-34059 - An SQL injection vulnerability exists in the...
An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to...
NA - CVE-2025-34060 - A PHP objection injection vulnerability exists...
A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input in the /get/image/ endpoint. The application passes a...