Executive brief
A security vulnerability exists in the web management interface of AVTECH DGM1104 IP cameras, which are used for video surveillance. An attacker can inject malicious code into the camera's user management settings, which could allow them to hijack the sessions of legitimate administrators or perform unauthorized actions when the settings page is viewed. This could lead to unauthorized access to the camera's video feed or configuration.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the PwdGrp.cgi endpoint of AVTECH DGM1104 IP cameras. The root cause is improper neutralization of input in the username field during user creation. An attacker can inject a crafted payload into the username field; this script is then executed in the context of any user who subsequently visits the user list page in the web interface. While the NVD description suggests no preconditions, secondary research indicates this typically occurs during user creation, which may require authentication. Successful exploitation allows for arbitrary JavaScript execution, potentially leading to session hijacking or administrative credential theft.
Affected products
- AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003
Timeline
- 2025-05: disclosed: Vulnerability discovered by Lewis Patten
- 2025-12-03: advisory: CVE published and initial NVD entry created