6.5
CVSSv2

CVE-2020-29001

Published: 26/01/2021 Updated: 03/02/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

An issue exists on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote malicious user to take full control of the camera with a high-privileged account. The vulnerability exists because a static username and password are compiled into the ppsapp RESTful application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

merkuryinnovations geeni_gnc-cw028_firmware 2.7.2

merkuryinnovations geeni_gnc-cw025_firmware 2.9.5

merkuryinnovations merkury_mi-cw024_firmware 2.9.6

merkuryinnovations merkury_mi-cw017_firmware 2.9.6