AVTECH DVR Devices Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in multiple firmware versions of AVTECH DVR devices. This vulnerability allows attackers to access the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication. By manipulating the ip, port, and queryb64str parameters, attackers can send arbitrary HTTP requests from the DVR to internal or external systems, potentially exposing sensitive data or interacting with internal services.

Impact

Exploitation of this vulnerability allows for unauthorized HTTP requests to be made through the DVR device, which can be used to access internal systems or data.

Reproduction

The vulnerability can be reproduced by sending a request to the /cgi-bin/nobody/Search.cgi endpoint with the action parameter set to cgi_query. The ip, port, and queryb64str parameters can be modified to perform arbitrary HTTP requests through the DVR device.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
9.1
remediation
8.3
relevance
0.2
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.