Записи AVTECH
13 опубликованных записей вендора avtech.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-287 Improper Authentication1
- CWE-295 Improper Certificate Validation1
- CWE-297 Improper Validation of Certificate with Host Mismatch1
- CWE-668 Exposure of Resource to Wrong Sphere1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
46В плане | CVE-2024-7029Proof of concept | Command Injection in AVTech AVM1203 (IP Camera)avtech · avm1203 firmware · CWE-77 | Высокая8,7 | — | 39,0 % | 2 авг. 2024 г. |
43В плане | CVE-2013-4982Proof of concept | AVTECH AVN801 DVR has a security bypass via the administration login captchaavtech · avn801 dvr firmware · CWE-287 | Критическая9,8 | — | 13,1 % | 27 дек. 2019 г. |
40В плане | CVE-2025-57201Эксплойта нет | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability iavtech · dgm1104 firmware · CWE-77 | Высокая8,8 | — | 17,2 % | 3 дек. 2025 г. |
39Наблюдать | CVE-2025-46408Proof of concept | An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpCavtech · eagleeyes\(lite\) · CWE-297 | Критическая9,8 | — | 0,7 % | 15 сент. 2025 г. |
38Наблюдать | CVE-2013-4980Proof of concept | Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, aavtech · avn801 dvr firmware · CWE-119 | Критическая9,0 | — | 6,0 % | 3 мар. 2014 г. |
38Наблюдать | CVE-2013-4981Proof of concept | Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, aavtech · avn801 dvr firmware · CWE-119 | Критическая9,0 | — | 6,0 % | 3 мар. 2014 г. |
36Наблюдать | CVE-2025-57199Proof of concept | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability iavtech · dgm1104 firmware · CWE-77 | Высокая8,8 | — | 3,3 % | 3 дек. 2025 г. |
36Наблюдать | CVE-2019-13379Эксплойта нет | On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenavtech · room alert 3e firmware · CWE-668 | Высокая8,8 | — | 3,0 % | 7 июл. 2019 г. |
36Наблюдать | CVE-2025-57198Эксплойта нет | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability iavtech · dgm1104 firmware · CWE-77 | Высокая8,8 | — | 2,8 % | 3 дек. 2025 г. |
35Наблюдать | CVE-2025-50944Proof of concept | An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0.avtech · eagleeyes\(lite\) · CWE-295 | Высокая8,8 | — | 0,3 % | 15 сент. 2025 г. |
31Наблюдать | CVE-2008-3939Эксплойта нет | Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary filavtech · pager enterprise · CWE-22 | Высокая7,5 | — | 1,7 % | 5 сент. 2008 г. |
27Наблюдать | CVE-2025-57200Эксплойта нет | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability iavtech · dgm1104 firmware · CWE-77 | Средняя6,5 | — | 2,4 % | 3 дек. 2025 г. |
24Наблюдать | CVE-2025-57202Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1avtech · dgm1104 firmware · CWE-79 | Средняя6,1 | — | 0,5 % | 3 дек. 2025 г. |
- CVE-2024-702946В плане
Command Injection in AVTech AVM1203 (IP Camera)
ВысокаяCVSS 8,7Proof of conceptEPSS 39 %avtech · avm1203 firmware2 авг. 2024 г.
- CVE-2013-498243В плане
AVTECH AVN801 DVR has a security bypass via the administration login captcha
КритическаяCVSS 9,8Proof of conceptEPSS 13 %avtech · avn801 dvr firmware27 дек. 2019 г.
- CVE-2025-5720140В плане
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability i
ВысокаяCVSS 8,8Эксплойта нетEPSS 17 %avtech · dgm1104 firmware3 дек. 2025 г.
- CVE-2025-4640839Наблюдать
An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpC
КритическаяCVSS 9,8Proof of conceptEPSS 1 %avtech · eagleeyes\(lite\)15 сент. 2025 г.
- CVE-2013-498038Наблюдать
Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, a
КритическаяCVSS 9,0Proof of conceptEPSS 6 %avtech · avn801 dvr firmware3 мар. 2014 г.
- CVE-2013-498138Наблюдать
Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, a
КритическаяCVSS 9,0Proof of conceptEPSS 6 %avtech · avn801 dvr firmware3 мар. 2014 г.
- CVE-2025-5719936Наблюдать
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability i
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %avtech · dgm1104 firmware3 дек. 2025 г.
- CVE-2019-1337936Наблюдать
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthen
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %avtech · room alert 3e firmware7 июл. 2019 г.
- CVE-2025-5719836Наблюдать
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability i
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %avtech · dgm1104 firmware3 дек. 2025 г.
- CVE-2025-5094435Наблюдать
An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0.
ВысокаяCVSS 8,8Proof of conceptEPSS 0 %avtech · eagleeyes\(lite\)15 сент. 2025 г.
- CVE-2008-393931Наблюдать
Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary fil
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %avtech · pager enterprise5 сент. 2008 г.
- CVE-2025-5720027Наблюдать
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability i
СредняяCVSS 6,5Эксплойта нетEPSS 2 %avtech · dgm1104 firmware3 дек. 2025 г.
- CVE-2025-5720224Наблюдать
A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1
СредняяCVSS 6,1Эксплойта нетEPSS 0 %avtech · dgm1104 firmware3 дек. 2025 г.