Executive brief
The AVTECH DGM3103SCT is an IP camera used for security surveillance. A vulnerability in its web management interface allows an authorized user to execute unauthorized system commands. If exploited, an attacker could take full control of the camera with administrative privileges, potentially leading to unauthorized video access, service disruption, or use of the device as a foothold in the local network.
Technical details
An OS command injection vulnerability (CWE-78) exists in the AVTECH DGM3103SCT IP camera firmware version 3.2.5.4 and prior. The flaw is located within the web management console, where improper neutralization of special elements allows for the execution of arbitrary system commands. An attacker must have network access and valid credentials for a high-privileged account (PR:H) to exploit this vulnerability. Successful exploitation results in full system compromise with root-level privileges. Users are advised to update to the latest firmware version provided by the vendor.
Affected products
- AVTECH Security Corporation DGM3103SCT 3.2.5.4 and prior
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory