AVTECH DVRs
cpe:2.3:h:avtech:avn801_dvr:*:*:*:*:*:*:*, +1 more
A vulnerability allowing unauthenticated access to sensitive internal device information exists in AVTECH IP cameras, DVRs, and NVRs. This issue can be exploited via the 'Machine.cgi?action=get_capability' request, which discloses details such as the firmware version, MAC address, and codec support without requiring authentication.
Exploitation of this vulnerability leads to unauthorized access to sensitive device information, including firmware versions, MAC addresses, and supported codecs.
The vulnerability can be reproduced by sending a GET request to '/cgi-bin/nobody/Machine.cgi' with the 'action=get_capability' parameter. This request can be made without any authentication, and the response will include sensitive information such as the firmware version, MAC address, and product type.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.