CVE-2025-34050
BaseFortify
Publication date: 2025-07-01
Last updated on: 2025-07-03
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-352 | The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a cross-site request forgery (CSRF) in the web interface of AVTECH IP camera, DVR, and NVR devices. It allows an attacker to create malicious requests that, when executed in the context of an authenticated user's browser session, can make unauthorized changes to the device configuration without the user's interaction.
How can this vulnerability impact me? :
The vulnerability can allow attackers to change the configuration of your AVTECH IP camera, DVR, or NVR devices without your consent or knowledge, potentially compromising device security and functionality.