CVE-2025-34053
BaseFortify
Publication date: 2025-07-01
Last updated on: 2025-07-03
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-290 | This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an authentication bypass in AVTECH IP camera, DVR, and NVR devices' streamd web server. It occurs because the strstr() function is used to detect ".cab" requests, which allows any URL containing ".cab" to bypass authentication and access protected endpoints without proper authorization.
How can this vulnerability impact me? :
This vulnerability can allow unauthorized users to bypass authentication and gain access to protected endpoints on AVTECH IP camera, DVR, and NVR devices. This could lead to unauthorized viewing, control, or manipulation of the devices, potentially compromising security and privacy.