Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 2.5% | — | Avtech Dgm3103sctAI | 30/6/2026 | 30/6/2026 | DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who can log in to the web management console of the affected product. | |
| Modificada | Media (6.1) | 0.48% | — | Avtech Dgm1104 Firmware | 3/12/2025 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the username field. | |
| Modificada | Alta (8.8) | 17% | — | Avtech Dgm1104 Firmware | 3/12/2025 | 5/7/2026 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |
| Modificada | Alta (8.8) | 3.3% | — | Avtech Dgm1104 Firmware | 3/12/2025 | 5/7/2026 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |
| Modificada | Alta (8.8) | 2.8% | — | Avtech Dgm1104 Firmware | 3/12/2025 | 5/7/2026 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine.cgi endpoint. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |
| Modificada | Media (6.5) | 2.4% | — | Avtech Dgm1104 Firmware | 3/12/2025 | 5/7/2026 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the test_mail function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |
| Aplazada | Alta (8.7) | 3.9% | — | Avtech Cloudsetup.cgiAI | 9/10/2025 | 17/6/2026 | AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can… | |
| Analizada | Alta (8.8) | 0.27% | — | Avtech Eagleeyes(lite) | 15/9/2025 | 17/6/2026 | An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificate's expiration date, skipping proper TLS chain validation. | |
| Aplazada | Alta (8.8) | 0.27% | — | Avtech Eagleeyes LiteAI | 15/9/2025 | 17/6/2026 | An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS | |
| Analizada | Crítica (9.8) | 0.66% | — | Avtech Eagleeyes(lite) | 15/9/2025 | 17/6/2026 | An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOW_ALL_HOSTNAME_VERIFIER, bypassing domain validation. | |
| Aplazada | Alta (8.3) | 0.32% | — | Avtech IP CamerasAIAvtech DVRAIAvtech NVRAI | 1/7/2025 | 17/6/2026 | An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks. | |
| Aplazada | Media (6.9) | 0.62% | — | Avtech IP CameraAIAvtech DVRAIAvtech NVRAI | 1/7/2025 | 17/6/2026 | An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls. | |
| Aplazada | Crítica (9.4) | 1.8% | — | Avtech IP CameraAIAvtech DVRAIAvtech NVRAI | 1/7/2025 | 17/6/2026 | An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group management operations. Authenticated users can supply input through the pwd or grp parameters, which are directly embedded into system commands without proper sanitation.… | |
| Aplazada | Crítica (9.4) | 1.5% | — | Avtech DVRAIAvtech NVRAIAvtech IP CameraAI | 1/7/2025 | 17/6/2026 | An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the ActionD daemon. Authenticated users can invoke the DoShellCmd operation, passing arbitrary input via the strCmd parameter. This input is executed directly by the system… | |
| Aplazada | Crítica (10) | 2.7% | — | Avtech DVRAI | 1/7/2025 | 17/6/2026 | An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the… | |
| Aplazada | Media (6.9) | 0.63% | — | Avtech IP CameraAIAvtech DVRAIAvtech NVRAI | 1/7/2025 | 17/6/2026 | An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints. | |
| Aplazada | Media (6.9) | 0.58% | — | Avtech DVRAI | 1/7/2025 | 17/6/2026 | A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication. An attacker can manipulate the ip, port, and queryb64str parameters to make arbitrary HTTP requests from the DVR to… | |
| Aplazada | Media (5.1) | 0.28% | — | Avtech IP CameraAIAvtech DVRAIAvtech NVRAI | 1/7/2025 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user… | |
| Analizada | Alta (8.7) | 39% | — | Avtech Avm1203 Firmware | 2/8/2024 | 17/6/2026 | Commands can be injected over the network and executed without authentication. | |
| Aplazada | Alta (7.2) | 0.29% | — | Avtech Room Alert 4EAI | 24/5/2024 | 17/6/2026 | An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in plaintext via a crafted AJAX request. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Aplazada | Media (4.9) | 0.24% | — | Avtech Room Alert 4EAI | 24/5/2024 | 17/6/2026 | An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passback attack. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Modificada | Crítica (9.8) | 13% | — | Avtech Avn801 DVR Firmware | 27/12/2019 | 16/6/2026 | AVTECH AVN801 DVR has a security bypass via the administration login captcha | |
| Modificada | Alta (8.8) | 3.0% | — | Avtech Room Alert 3E Firmware | 7/7/2019 | 17/6/2026 | On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in. | |
| Modificada | Alta (9) | 6.0% | — | Avtech Avn801 DVR FirmwareAvtech Avn801 DVR | 3/3/2014 | 16/6/2026 | Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the Network.SMTP.Receivers parameter. | |
| Modificada | Alta (9) | 6.0% | — | Avtech Avn801 DVR FirmwareAvtech Avn801 DVR | 3/3/2014 | 16/6/2026 | Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the URI in an RTSP SETUP request. |