AVTECH records
13 published records for vendor avtech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-287 Improper Authentication1
- CWE-295 Improper Certificate Validation1
- CWE-297 Improper Validation of Certificate with Host Mismatch1
- CWE-668 Exposure of Resource to Wrong Sphere1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2024-7029Proof of concept | Command Injection in AVTech AVM1203 (IP Camera)avtech · avm1203 firmware · CWE-77 | High8.7 | — | 39.0% | Aug 2, 2024 |
43Plan | CVE-2013-4982Proof of concept | AVTECH AVN801 DVR has a security bypass via the administration login captchaavtech · avn801 dvr firmware · CWE-287 | Critical9.8 | — | 13.1% | Dec 27, 2019 |
40Plan | CVE-2025-57201No exploit | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability iavtech · dgm1104 firmware · CWE-77 | High8.8 | — | 17.2% | Dec 3, 2025 |
39Monitor | CVE-2025-46408Proof of concept | An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpCavtech · eagleeyes\(lite\) · CWE-297 | Critical9.8 | — | 0.7% | Sep 15, 2025 |
38Monitor | CVE-2013-4980Proof of concept | Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, aavtech · avn801 dvr firmware · CWE-119 | Critical9.0 | — | 6.0% | Mar 3, 2014 |
38Monitor | CVE-2013-4981Proof of concept | Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, aavtech · avn801 dvr firmware · CWE-119 | Critical9.0 | — | 6.0% | Mar 3, 2014 |
36Monitor | CVE-2025-57199Proof of concept | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability iavtech · dgm1104 firmware · CWE-77 | High8.8 | — | 3.3% | Dec 3, 2025 |
36Monitor | CVE-2019-13379No exploit | On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenavtech · room alert 3e firmware · CWE-668 | High8.8 | — | 3.0% | Jul 7, 2019 |
36Monitor | CVE-2025-57198No exploit | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability iavtech · dgm1104 firmware · CWE-77 | High8.8 | — | 2.8% | Dec 3, 2025 |
35Monitor | CVE-2025-50944Proof of concept | An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0.avtech · eagleeyes\(lite\) · CWE-295 | High8.8 | — | 0.3% | Sep 15, 2025 |
31Monitor | CVE-2008-3939No exploit | Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary filavtech · pager enterprise · CWE-22 | High7.5 | — | 1.7% | Sep 5, 2008 |
27Monitor | CVE-2025-57200No exploit | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability iavtech · dgm1104 firmware · CWE-77 | Medium6.5 | — | 2.4% | Dec 3, 2025 |
24Monitor | CVE-2025-57202No exploit | A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1avtech · dgm1104 firmware · CWE-79 | Medium6.1 | — | 0.5% | Dec 3, 2025 |
- CVE-2024-702946Plan
Command Injection in AVTech AVM1203 (IP Camera)
HighCVSS 8.7Proof of conceptEPSS 39%avtech · avm1203 firmwareAug 2, 2024
- CVE-2013-498243Plan
AVTECH AVN801 DVR has a security bypass via the administration login captcha
CriticalCVSS 9.8Proof of conceptEPSS 13%avtech · avn801 dvr firmwareDec 27, 2019
- CVE-2025-5720140Plan
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability i
HighCVSS 8.8No exploitEPSS 17%avtech · dgm1104 firmwareDec 3, 2025
- CVE-2025-4640839Monitor
An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpC
CriticalCVSS 9.8Proof of conceptEPSS 1%avtech · eagleeyes\(lite\)Sep 15, 2025
- CVE-2013-498038Monitor
Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, a
CriticalCVSS 9.0Proof of conceptEPSS 6%avtech · avn801 dvr firmwareMar 3, 2014
- CVE-2013-498138Monitor
Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, a
CriticalCVSS 9.0Proof of conceptEPSS 6%avtech · avn801 dvr firmwareMar 3, 2014
- CVE-2025-5719936Monitor
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability i
HighCVSS 8.8Proof of conceptEPSS 3%avtech · dgm1104 firmwareDec 3, 2025
- CVE-2019-1337936Monitor
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthen
HighCVSS 8.8No exploitEPSS 3%avtech · room alert 3e firmwareJul 7, 2019
- CVE-2025-5719836Monitor
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability i
HighCVSS 8.8No exploitEPSS 3%avtech · dgm1104 firmwareDec 3, 2025
- CVE-2025-5094435Monitor
An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0.
HighCVSS 8.8Proof of conceptEPSS 0%avtech · eagleeyes\(lite\)Sep 15, 2025
- CVE-2008-393931Monitor
Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary fil
HighCVSS 7.5No exploitEPSS 2%avtech · pager enterpriseSep 5, 2008
- CVE-2025-5720027Monitor
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability i
MediumCVSS 6.5No exploitEPSS 2%avtech · dgm1104 firmwareDec 3, 2025
- CVE-2025-5720224Monitor
A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1
MediumCVSS 6.1No exploitEPSS 0%avtech · dgm1104 firmwareDec 3, 2025