PT-2020-6275 · Rubetek · Rv-3406+2

Sergey Zelensky

·

Published

2020-09-25

·

Updated

2021-07-21

·

CVE-2020-25747

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:P/A:C
Name of the Vulnerable Software and Affected Versions Rubetek RV-3406, RV-3409, and RV-3411 (affected versions not specified)
Description The issue is related to insufficient authentication in the Telnet service of the Wi-Fi camera's firmware, allowing a remote attacker to gain unauthorized access to RTSP and ONFIV services. This access enables the attacker to watch live streams from the camera, change camera settings, rotate the camera, restart it, or reset it to factory settings.
Recommendations For Rubetek RV-3406, RV-3409, and RV-3411, consider disabling the Telnet service until a patch is available to prevent unauthorized access. Restrict access to RTSP and ONFIV services to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03825
CVE-2020-25747

Affected Products

Rv-3406
Rv-3409
Rv-3411