Security Advisory
CVE-2025-34065
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function allows unauthenticated access to any request containing "/nobody" in the URL, bypassing login controls.