10
CVSSv2

CVE-2020-25749

Published: 25/09/2020 Updated: 08/10/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote malicious user to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rubetek rv-3406_firmware 339

rubetek rv-3406_firmware 342

rubetek rv-3409_firmware 339

rubetek rv-3409_firmware 342

rubetek rv-3411_firmware 339

rubetek rv-3411_firmware 342

Github Repositories

CVE-2020-25749

CVE-2020-25749 [Suggested description] The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account The vulnerability exists because a system account has a default and static password The Telnet service cannot be disabled and this pass