CVE-2025-34065 is an authentication bypass vulnerability affecting AVTECH IP camera, DVR, and NVR devices in the streamd web server. The issue is caused by improper authentication logic in request handling: the server uses strstr() to check for the substring "/nobody" in the requested URL, and any request containing that substring is treated as exempt from normal login enforcement. As a result, an unauthenticated remote attacker can craft requests with "/nobody" embedded in the URL to access functionality that should require prior authentication.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains two Python scripts and one documentation file focused on AVTECH DVR/NVR web interface weaknesses. The main analysis script, avtech_analyzer.py, is a multi-capability exploitation helper that builds HTTP requests to numerous CGI endpoints, enumerates device capabilities, tests authentication bypasses (.cab and /nobody variants), attempts credential extraction from Config.cgi, probes Search.cgi for SSRF-like behavior, and demonstrates multiple command-execution paths through CloudSetup.cgi, adcommand.cgi, and Search.cgi parameter injection. The script also parses firmware version, product type, product ID, and MAC address from Machine.cgi responses. The second script, pwdgrp_injection_poc.py, is a focused raw-socket PoC for command injection in /cgi-bin/supervisor/PwdGrp.cgi. It crafts a GET request where the pwd parameter is terminated and appended with arbitrary shell commands. Example commands include launching a telnet daemon with /bin/sh on port 23 and checking common directories for telnet binaries. This is active exploitation code rather than mere detection. Repository structure is minimal: .gitattributes, avtech_analyzer.py, docs, and pwdgrp_injection_poc.py. The docs file describes the PwdGrp.cgi issue as sanitized research material, but the included code still provides actionable exploitation logic and working command payload examples. Overall, the repository’s purpose is to analyze and exploit multiple AVTECH DVR/NVR CGI vulnerabilities, with emphasis on credential access and remote command execution over the network.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.