CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “avtech”

10 vulnerabilities found for “avtech”

CVE-2025-57199
HIGH8.8

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

avtech / dgm1104_firmware
Network
Published Dec 3, 2025
CVE-2025-57198
HIGH8.8

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine.cgi endpoint. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

avtech / dgm1104_firmware
Network
Published Dec 3, 2025
CVE-2025-57202
MEDIUM6.1

A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the username field.

avtech / dgm1104_firmware
Network
Published Dec 3, 2025
CVE-2025-57200
MEDIUM6.5

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the test_mail function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

avtech / dgm1104_firmware
Network
Published Dec 3, 2025
CVE-2025-57201
HIGH8.8

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

avtech / dgm1104_firmware
Network
Published Dec 3, 2025
CVE-2025-50944
HIGH8.8

An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificate's expiration date, skipping proper TLS chain validation.

avtech / eagleeyes\(lite\)
Network
Published Sep 15, 2025
CVE-2025-46408
CRITICAL9.8

An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOW_ALL_HOSTNAME_VERIFIER, bypassing domain validation.

avtech / eagleeyes\(lite\)
Network
Published Sep 15, 2025
CVE-2024-7029
HIGH8.8

Commands can be injected over the network and executed without authentication.

avtech / avm1203_firmware
Network
Published Aug 2, 2024
CVE-2013-4982
CRITICAL9.8

AVTECH AVN801 DVR has a security bypass via the administration login captcha

avtech / avn801_dvr_firmware
Network
Published Dec 27, 2019
CVE-2019-13379
HIGH8.8

On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.

avtech / room_alert_3e_firmware
Network
Published Jul 7, 2019