Executive brief
A security vulnerability has been identified in several AVTECH IP cameras, which are used for video surveillance and security monitoring. An attacker with valid login credentials can exploit the camera's file-sharing settings to take complete control of the device. This could allow an unauthorized person to view private video feeds, disable security monitoring, or use the camera as a foothold to attack other parts of the corporate network.
Technical details
A post-authentication command injection vulnerability exists in the SMB share functionality of the admin web interface across multiple AVTECH IP camera models. The flaw resides in the 'cgibox' binary, specifically within the function responsible for mounting remote SMB shares. The device retrieves saved SMB configuration settings from flash memory and passes them to the 'system()' function without proper sanitization. An authenticated attacker can provide maliciously crafted input to the web API to execute arbitrary commands with root privileges. While the advisory highlights the DGM1104 model, firmware analysis suggests dozens of other models (including AVM, AVN, and AVX series) are also affected.
Affected products
- AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003
- AVTECH SECURITY Corporation VM1203
- AVTECH SECURITY Corporation AVM2200
- AVTECH SECURITY Corporation AVM301
- AVTECH SECURITY Corporation AVN2503
- AVTECH SECURITY Corporation AVX931A
Timeline
- 2025-05: other: Vulnerability discovered by Lewis Patten
- 2025-12-03: advisory: Initial disclosure and CVE assignment