CVE-2025-34051 | AVTECH DVR up to V189-V189-V189-V189 Search.cgi?action=cgi_query queryb64str server-side request forgery (Exploit 40500 / EUVD-2025-19631)
A vulnerability classified as critical has been found in AVTECH DVR. Affected is an unknown function of the file /cgi-bin/nobody/Search.cgi?action=cgi_query. The manipulation of the argument queryb64str leads to server-side request forgery.
This vulnerability is traded as CVE-2025-34051. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.