PT-2025-50240 · Commax · Commax Smart Home System

Published

2025-12-09

·

Updated

2025-12-10

·

CVE-2021-47710

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions COMMAX Smart Home System (affected versions not specified)
Description An unauthenticated attacker can disclose RTSP credentials in plain text. This is achieved by exploiting the /overview.asp endpoint through a GET request. Successful exploitation allows access to sensitive information, including login credentials and DVR settings.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-47710

Affected Products

Commax Smart Home System