An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devicesβ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation5 reference(s) from NVD