CVE-2020-25748

HIGH

Rubetek Rv-3406 Firmware - Cleartext Transmission

Title source: rule
STIX 2.1

Description

A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the camera, which is transmitted in an unencrypted form. One can also modify responses from NTP and RTSP servers and force the camera to use the changed values.

Exploits (1)

nomisec WRITEUP 1 stars
by jet-pentest · poc
https://github.com/jet-pentest/CVE-2020-25748

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://github.com/jet-pentest/CVE-2020-25748

Scores

CVSS v3 8.1
EPSS 0.0022
EPSS Percentile 44.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-319
Status published
Products (6)
rubetek/rv-3406_firmware 339
rubetek/rv-3406_firmware 342
rubetek/rv-3409_firmware 339
rubetek/rv-3409_firmware 342
rubetek/rv-3411_firmware 339
rubetek/rv-3411_firmware 342
Published Sep 25, 2020
Tracked Since Feb 18, 2026