AVTECH IP Cameras, DVRs, and NVRs Authentication Bypass Vulnerability

Vulnerability

A vulnerability allowing authentication bypass has been identified in AVTECH IP cameras, DVR, and NVR devices. This issue resides within the streamd web server, where the strstr() function is used to bypass login controls. Unauthenticated access is granted to any request containing '/nobody' in the URL, allowing exploitation of various vulnerabilities, including command injection and information disclosure.

Impact

Exploitation of this vulnerability allows for authentication bypass, with subsequent access to sensitive information and the ability to execute commands on the device.

Reproduction

The vulnerability can be reproduced by sending a request to the streamd web server with '/nobody' included in the URL. This request will bypass authentication, allowing access to protected resources and functionalities. Once authenticated, the AVTECH CloudSetup.cgi and adcommand.cgi scripts can be used to execute arbitrary system commands with root privileges.

Remediation

Users are advised to change the default admin password and avoid exposing the web interface to the internet.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
9.1
remediation
8.3
relevance
0.2
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.