The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.

Project Subscriptions

Vendors Products
Rubetek Subscribe
Rv-3406 Subscribe
Rv-3406 Firmware Subscribe
Rv-3409 Subscribe
Rv-3409 Firmware Subscribe
Rv-3411 Subscribe
Rv-3411 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-18401 The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T15:40:36.961Z

Reserved: 2020-09-18T00:00:00

Link: CVE-2020-25749

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-25T04:23:05.167

Modified: 2024-11-21T05:18:39.247

Link: CVE-2020-25749

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses