CVE-2025-34050
Description
A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user interaction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A CSRF vulnerability in AVTECH IP cameras, DVRs, and NVRs allows attackers to modify device settings by tricking authenticated users into clicking a malicious link.
The web interface of AVTECH IP cameras, DVRs, and NVRs lacks cross-site request forgery (CSRF) protection, allowing an attacker to forge requests on behalf of an authenticated user [2][3]. This vulnerability is part of a larger set of issues identified in AVTECH devices, including plaintext password storage and unauthenticated information disclosure [3].
To exploit the CSRF vulnerability, an attacker crafts a malicious request and tricks an authenticated user into executing it, typically by hosting a specially crafted webpage. If the user has an active session, the attacker can change any device configuration without further interaction. Additionally, if the default admin password has not been changed, the attacker can log in via CSRF and then perform arbitrary actions [2][3].
Successful exploitation allows an attacker to modify device settings, potentially gaining persistent access to the device, disrupting surveillance operations, or using the device as a pivot for further attacks. Since many AVTECH devices are exposed to the internet (over 130,000 according to Shodan), this vulnerability poses a significant risk [3].
AVTECH has not released an official patch for this vulnerability, though users are advised to update to the latest firmware and change default passwords. Given the age of the advisory (first published in 2016) and the continued exposure of devices, this vulnerability may still be exploitable in unpatched systems [1][2].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- avtech.comnvd
- vulncheck.com/advisories/avtech-ipcamera-nvr-dvr-mulitple-vulnsnvd
- web.archive.org/web/20161029201749/https://github.com/ebux/AVTECHnvd
- web.archive.org/web/20240810225729/https://www.search-lab.hu/advisories/126-AVTech-devices-multiple-vulnerabilitiesnvd
- www.exploit-db.com/exploits/40500nvd
News mentions
0No linked articles in our index yet.