Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3gm-j47f-vqgx

Опубликовано: 01 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication. An attacker can manipulate the ip, port, and queryb64str parameters to make arbitrary HTTP requests from the DVR to internal or external systems, potentially exposing sensitive data or interacting with internal services.

A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication. An attacker can manipulate the ip, port, and queryb64str parameters to make arbitrary HTTP requests from the DVR to internal or external systems, potentially exposing sensitive data or interacting with internal services.

EPSS

Процентиль: 29%
0.00106
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-200

Связанные уязвимости

nvd
7 месяцев назад

A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication. An attacker can manipulate the ip, port, and queryb64str parameters to make arbitrary HTTP requests from the DVR to internal or external systems, potentially exposing sensitive data or interacting with internal services.

EPSS

Процентиль: 29%
0.00106
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-200