Executive brief
A security vulnerability has been identified in several AVTECH IP cameras, which are used for video surveillance and security monitoring. An attacker with access to the camera's administrative interface can execute unauthorized commands on the device. This could allow a malicious actor to take full control of the camera, potentially leading to unauthorized surveillance, data theft, or using the device as a foothold to attack other parts of the corporate network.
Technical details
A post-authentication command injection vulnerability exists in the 'test_mail' function within the 'cgibox' binary of various AVTECH IP cameras. The vulnerability occurs because the device reads SMTP configuration settings from flash memory and integrates them into a string passed directly to the 'system()' function without proper sanitization. An authenticated attacker can exploit this by supplying maliciously crafted input to the web API, resulting in arbitrary command execution with root privileges. While the NVD entry lists DGM1104, security researchers have identified dozens of additional models (AVM, AVN, DGM, AVC, KPD, and AVX series) as potentially vulnerable based on firmware analysis.
Affected products
- AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003
- AVTECH SECURITY Corporation AVM1203
- AVTECH SECURITY Corporation AVM2200
- AVTECH SECURITY Corporation AVM301
- AVTECH SECURITY Corporation AVN808
- AVTECH SECURITY Corporation DGM1304
- AVTECH SECURITY Corporation AVC704H
Timeline
- 2025-05: disclosed: Vulnerability discovered by Lewis Patten
- 2025-12-03: advisory: CVE published by NVD/MITRE