Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cwg-hq24-8wr2

Опубликовано: 01 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.

EPSS

Процентиль: 29%
0.00107
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-290

Связанные уязвимости

nvd
7 месяцев назад

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.

EPSS

Процентиль: 29%
0.00107
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-290