AVTECH IP Cameras, DVRs, and NVRs Unauthenticated Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing unauthenticated access to sensitive internal device information exists in AVTECH IP cameras, DVRs, and NVRs. This issue can be exploited via the 'Machine.cgi?action=get_capability' request, which discloses details such as the firmware version, MAC address, and codec support without requiring authentication.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive device information, including firmware versions, MAC addresses, and supported codecs.

Reproduction

The vulnerability can be reproduced by sending a GET request to '/cgi-bin/nobody/Machine.cgi' with the 'action=get_capability' parameter. This request can be made without any authentication, and the response will include sensitive information such as the firmware version, MAC address, and product type.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
9.1
remediation
8.3
relevance
0.2
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.