Vulnerabilities > Avtech

DATE CVE VULNERABILITY TITLE RISK
2024-08-02 CVE-2024-7029 Command Injection vulnerability in Avtech Avm1203 Firmware
Commands can be injected over the network and executed without authentication.
network
low complexity
avtech CWE-77
critical
9.8
2019-12-27 CVE-2013-4982 Improper Authentication vulnerability in Avtech Avn801 DVR Firmware 1017100310091003
AVTECH AVN801 DVR has a security bypass via the administration login captcha
network
low complexity
avtech CWE-287
critical
9.8
2019-07-07 CVE-2019-13379 Exposure of Resource to Wrong Sphere vulnerability in Avtech Room Alert 3E Firmware
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.
network
low complexity
avtech CWE-668
8.8