CVE-2025-34052

An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and NVRs via Machine.cgi?action=get_capability. Sensitive internal device information such as firmware version, MAC address, and codec support can be accessed without authentication.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Jul 2025, 15:14

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de divulgación de información no autenticada en AVTECH IP cameras, DVRs, y NVRs mediante Machine.cgi?action=get_capability. Se puede acceder sin autenticación a información confidencial interna del dispositivo, como la versión del firmware, la dirección MAC y la compatibilidad de códecs.

01 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-01 15:15

Updated : 2025-07-03 15:14


NVD link : CVE-2025-34052

Mitre link : CVE-2025-34052

CVE.ORG link : CVE-2025-34052


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-306

Missing Authentication for Critical Function