Junglewise Threat Intelligence

CVE-2025-57202: AVTECH DGM1104 Stored XSS in PwdGrp.cgi username field

CVE-2025-57202 · Severity: medium · CVSS 6.1 · Published 2025-12-03

Technologies: Avtech Dgm1104 Firmware, Avtech Dgm1104. Vendors: Avtech, AVTECH SECURITY Corporation.

Executive brief

A security vulnerability exists in the web management interface of AVTECH DGM1104 IP cameras, which are used for video surveillance. An attacker can inject malicious code into the camera's user management settings, which could allow them to hijack the sessions of legitimate administrators or perform unauthorized actions when the settings page is viewed. This could lead to unauthorized access to the camera's video feed or configuration.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the PwdGrp.cgi endpoint of AVTECH DGM1104 IP cameras. The root cause is improper neutralization of input in the username field during user creation. An attacker can inject a crafted payload into the username field; this script is then executed in the context of any user who subsequently visits the user list page in the web interface. While the NVD description suggests no preconditions, secondary research indicates this typically occurs during user creation, which may require authentication. Successful exploitation allows for arbitrary JavaScript execution, potentially leading to session hijacking or administrative credential theft.

Affected products

  • AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003

Timeline

  • 2025-05: disclosed: Vulnerability discovered by Lewis Patten
  • 2025-12-03: advisory: CVE published and initial NVD entry created

References

Related threats