PT-2020-6277 · Rubetek · Rv-3406+2

Sergey Zelensky

·

Published

2020-09-25

·

Updated

2020-10-08

·

CVE-2020-25749

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rubetek cameras RV-3406, RV-3409, and RV-3411 firmware versions v342, v339
Description The issue is related to the Telnet service of the affected cameras, which allows a remote attacker to gain full control of the device using a high-privileged account. This is due to a system account having a default and static password that cannot be changed via standard functionality. The Telnet service itself cannot be disabled.
Recommendations For firmware versions v342 and v339, consider disabling the Telnet service as a temporary workaround, if possible, until a patch is available. However, since the Telnet service cannot be disabled and the password cannot be changed, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03827
CVE-2020-25749

Affected Products

Rv-3406
Rv-3409
Rv-3411