PT-2020-6275 · Rubetek · Rv-3406+2
Sergey Zelensky
·
Published
2020-09-25
·
Updated
2021-07-21
·
CVE-2020-25747
CVSS v2.0
9.7
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Rubetek RV-3406, RV-3409, and RV-3411 (affected versions not specified)
Description
The issue is related to insufficient authentication in the Telnet service of the Wi-Fi camera's firmware, allowing a remote attacker to gain unauthorized access to RTSP and ONFIV services. This access enables the attacker to watch live streams from the camera, change camera settings, rotate the camera, restart it, or reset it to factory settings.
Recommendations
For Rubetek RV-3406, RV-3409, and RV-3411, consider disabling the Telnet service until a patch is available to prevent unauthorized access.
Restrict access to RTSP and ONFIV services to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rv-3406
Rv-3409
Rv-3411