An unauthenticated information disclosure vulnerability exists in AVTECH IP cameras, DVRs, and NVRs via Machine.cgi?action=get_capability. Sensitive internal device information such as firmware version, MAC address, and codec support can be accessed without authentication.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/40500 | exploit |
https://avtech.com/ | product |
https://web.archive.org/web/20240810225729/https://www.search-lab.hu/advisories/126-AVTech-devices-multiple-vulnerabilities | technical description third party advisory |
https://web.archive.org/web/20161029201749/https://github.com/ebux/AVTECH | exploit |
https://vulncheck.com/advisories/avtech-ipcamera-nvr-dvr-mulitple-vulns | third party advisory |