CVE-2025-45620

8.1

Aver · PTC310UV2

A vulnerability in the Aver PTC310UV2 camera allows remote attackers to obtain sensitive information via a crafted network request.

Executive summary

An unauthenticated remote information disclosure vulnerability in the Aver PTC310UV2 camera poses a significant risk to data confidentiality.

Vulnerability

This vulnerability involves a flaw that allows an unauthenticated remote attacker to perform unauthorized data extraction through a crafted request.

Business impact

The ability for an unauthenticated actor to remotely access sensitive information could lead to the exposure of proprietary data or configuration details, potentially facilitating further network compromise. With a CVSS score of 8.1, this high-severity flaw represents a substantial threat to organizational security and operational integrity.

Remediation

Immediate Action: Contact the vendor or monitor the official Aver support portal for firmware updates addressing this information disclosure, as no specific patch version is currently provided.

Proactive Monitoring: Monitor network traffic for unusual outbound requests or anomalous access patterns originating from the PTC310UV2 device.

Compensating Controls: Deploy a network-level firewall or Web Application Firewall (WAF) to restrict access to the device management interface to trusted internal segments only.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists as documented in the referenced GitHub repository.

Analyst recommendation

Given the high CVSS score and the existence of a public proof-of-concept, this vulnerability should be prioritized for mitigation. Organizations using the Aver PTC310UV2 should restrict network access to the device immediately while awaiting a definitive firmware patch from the vendor to remediate the underlying flaw.

More Aver CVEs

Sources