← Back

CVE-2020-25749

nvd nist
Published: Sep 25, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.

Affected (6)

3 products
Rv 3406 Firmware
Rv 3409 Firmware
Rv 3411 Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Rubetek
Version 339
Version 342
Running on/withPlatform Versions
Rubetek
Rv 3406
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Rubetek
Version 339
Version 342
Running on/withPlatform Versions
Rubetek
Rv 3409
All versions
Configuration C
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Rubetek
Version 339
Version 342
Running on/withPlatform Versions
Rubetek
Rv 3411
All versions

References (2)

Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.