Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)2.5%—Avtech Dgm3103sctAI30/6/202630/6/2026
DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who can log in to the web management console of the affected product.
ModificadaMedia (6.1)0.48%—Avtech Dgm1104 Firmware3/12/20255/7/2026
A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the username field.
ModificadaAlta (8.8)17%—Avtech Dgm1104 Firmware3/12/20255/7/2026
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.
ModificadaAlta (8.8)3.3%—Avtech Dgm1104 Firmware3/12/20255/7/2026
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary. This vulnerability allows attackers to execute arbitrary commands via a crafted input.
ModificadaAlta (8.8)2.8%—Avtech Dgm1104 Firmware3/12/20255/7/2026
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine.cgi endpoint. This vulnerability allows attackers to execute arbitrary commands via a crafted input.
ModificadaMedia (6.5)2.4%—Avtech Dgm1104 Firmware3/12/20255/7/2026
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the test_mail function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.
AplazadaAlta (8.7)3.9%—Avtech Cloudsetup.cgiAI9/10/202517/6/2026
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can…
AnalizadaAlta (8.8)0.27%—Avtech Eagleeyes(lite)15/9/202517/6/2026
An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificate's expiration date, skipping proper TLS chain validation.
AplazadaAlta (8.8)0.27%—Avtech Eagleeyes LiteAI15/9/202517/6/2026
An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS
AnalizadaCrítica (9.8)0.66%—Avtech Eagleeyes(lite)15/9/202517/6/2026
An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOW_ALL_HOSTNAME_VERIFIER, bypassing domain validation.
AplazadaAlta (8.3)0.32%—Avtech IP CamerasAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.
AplazadaMedia (6.9)0.62%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.
AplazadaCrítica (9.4)1.8%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, which handles user and group management operations. Authenticated users can supply input through the pwd or grp parameters, which are directly embedded into system commands without proper sanitation.…
AplazadaCrítica (9.4)1.5%—Avtech DVRAIAvtech NVRAIAvtech IP CameraAI1/7/202517/6/2026
An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint, which interfaces with the ActionD daemon. Authenticated users can invoke the DoShellCmd operation, passing arbitrary input via the strCmd parameter. This input is executed directly by the system…
AplazadaCrítica (10)2.7%—Avtech DVRAI1/7/202517/6/2026
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str parameters, executing commands as root. Exploitation evidence was observed by the…
AplazadaMedia (6.9)0.63%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.
AplazadaMedia (6.9)0.58%—Avtech DVRAI1/7/202517/6/2026
A server-side request forgery vulnerability exists in multiple firmware versions of AVTECH DVR devices that exposes the /cgi-bin/nobody/Search.cgi?action=cgi_query endpoint without authentication. An attacker can manipulate the ip, port, and queryb64str parameters to make arbitrary HTTP requests from the DVR to…
AplazadaMedia (5.1)0.28%—Avtech IP CameraAIAvtech DVRAIAvtech NVRAI1/7/202517/6/2026
A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malicious requests that, when executed in the context of an authenticated user’s browser session, allow unauthorized changes to the device configuration without user…
AnalizadaAlta (8.7)39%—Avtech Avm1203 Firmware2/8/202417/6/2026
Commands can be injected over the network and executed without authentication.
AplazadaAlta (7.2)0.29%—Avtech Room Alert 4EAI24/5/202417/6/2026
An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in plaintext via a crafted AJAX request. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
AplazadaMedia (4.9)0.24%—Avtech Room Alert 4EAI24/5/202417/6/2026
An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in plaintext via a passback attack. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
ModificadaCrítica (9.8)13%—Avtech Avn801 DVR Firmware27/12/201916/6/2026
AVTECH AVN801 DVR has a security bypass via the administration login captcha
ModificadaAlta (8.8)3.0%—Avtech Room Alert 3E Firmware7/7/201917/6/2026
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.
ModificadaAlta (9)6.0%—Avtech Avn801 DVR FirmwareAvtech Avn801 DVR3/3/201416/6/2026
Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the Network.SMTP.Receivers parameter.
ModificadaAlta (9)6.0%—Avtech Avn801 DVR FirmwareAvtech Avn801 DVR3/3/201416/6/2026
Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the URI in an RTSP SETUP request.