CVE-2025-57199
8.8AVTECH SECURITY Corporation · DGM1104
The AVTECH DGM1104 surveillance device contains an authenticated command injection vulnerability in the NetFailDetectD binary, allowing arbitrary command execution via crafted input.
Executive summary
An authenticated command injection vulnerability in AVTECH DGM1104 devices poses a high risk of total system compromise through arbitrary code execution.
Vulnerability
The vulnerability exists in the NetFailDetectD binary, which fails to properly sanitize input, allowing an authenticated user to inject and execute arbitrary system commands. The CVSS vector PR:L confirms that the attacker must have low-level access to the device to trigger this flaw.
Business impact
The ability to execute arbitrary commands on a surveillance device creates a severe risk of unauthorized system control, potential lateral movement within the network, and the compromise of sensitive video feeds. With a CVSS score of 8.8, this vulnerability is categorized as High severity, reflecting the potential for full confidentiality, integrity, and availability loss.
Remediation
Immediate Action: Restrict network access to the affected devices to trusted administrators only, as a vendor patch is currently not confirmed.
Proactive Monitoring: Monitor system logs for unusual process execution or attempts to interact with the NetFailDetectD binary that deviate from standard operational patterns.
Compensating Controls: Implement strict network segmentation to isolate these devices from critical business infrastructure and utilize a WAF or IDS to inspect traffic for injection patterns targeting device management interfaces.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the researcher's repository.
Analyst recommendation
Given the availability of a public proof-of-concept, organizations should prioritize isolating the DGM1104 devices from untrusted networks immediately. Since no official patch is currently identified, applying network-level restrictions is the primary method to mitigate the risk of exploitation until official guidance or firmware updates are provided by AVTECH SECURITY Corporation.