Junglewise Threat Intelligence

CVE-2025-57198: AVTECH IP Cameras authenticated command injection in Machine.cgi

CVE-2025-57198 · Severity: high · CVSS 8.8 · Published 2025-12-03

Technologies: Avtech Dgm1104 Firmware, AVTECH SECURITY Corporation AVM1203, Avtech Dgm1104, AVTECH SECURITY Corporation AVM2200. Vendors: AVTECH SECURITY Corporation, Avtech.

Executive brief

A security vulnerability has been identified in several AVTECH IP camera models, which are used for video surveillance and security monitoring. An attacker with valid login credentials can exploit a flaw in the camera's web interface to take full control of the device. This could allow an unauthorized user to disrupt video feeds, access sensitive recordings, or use the camera as a foothold to attack other parts of the corporate network.

Technical details

A post-authentication command injection vulnerability exists in the 'Machine.cgi' endpoint of various AVTECH IP cameras. The flaw is located within the FTP test functionality in the 'cgibox' binary. The application fails to sanitize FTP configuration settings retrieved from flash memory before passing them to the 'system()' function. An authenticated attacker can provide maliciously crafted input to the web API to execute arbitrary commands with root privileges. While the advisory highlights the DGM1104 model, analysis of firmware images suggests dozens of other models in the AVM, AVN, DGM, AVC, and KPD series are also affected.

Affected products

  • AVTECH SECURITY Corporation DGM1104 firmware FullImg-1015-1004-1006-1003 FullImg-1015-1004-1006-1003
  • AVTECH SECURITY Corporation AVM1203
  • AVTECH SECURITY Corporation AVM2200
  • AVTECH SECURITY Corporation AVN815EZ
  • AVTECH SECURITY Corporation DGM1304QS

Timeline

  • 2025-12-03: disclosed
  • 2025-12-03: advisory

References

Related threats