AVTECH IP Camera, DVR, and NVR OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in AVTECH IP cameras, DVRs, and NVRs, through the PwdGrp.cgi endpoint, which manages user and group operations. This vulnerability allows authenticated users to execute arbitrary shell commands with root privileges by injecting commands into the pwd or grp parameters, which are not properly sanitized before being executed. The issue is present in all AVTECH devices and firmware versions.

Impact

Exploitation of this vulnerability allows for unauthorized execution of commands with root privileges on the affected device.

Reproduction

The vulnerability can be reproduced by sending a request to the PwdGrp.cgi endpoint with injected commands in the pwd or grp parameters. This can be done using a tool like curl or Postman, or through a custom script that automates the process. After authentication, the injected commands will be executed with root privileges, allowing for complete control over the device.

Remediation

Users are advised to change the default admin password and operate the devices behind a firewall. AVTECH has released firmware updates for some vulnerabilities, but it is unclear if this specific issue has been addressed.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
6.2
remediation
8.3
relevance
0.2
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.