CVE-2020-25748

HIGH

Rubetek RV-3406, RV-3409, and RV-3411 Firmware v342, v339 - Cleartext Transmission of Sensitive Information

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-25748. PoCs published by jet-pentest.

AI-analyzed exploit summary This repository contains a writeup describing CVE-2020-25748, a cleartext transmission vulnerability in Rubetek RV-3406, RV-3409, and RV-3411 cameras. The vulnerability allows interception and modification of video data, NTP, and RTSP responses due to unencrypted transmission.

Description

A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the video data from the camera, which is transmitted in an unencrypted form. One can also modify responses from NTP and RTSP servers and force the camera to use the changed values.

Exploits (1)

nomisec WRITEUP 1 stars
by jet-pentest · poc
https://github.com/jet-pentest/CVE-2020-25748

This repository contains a writeup describing CVE-2020-25748, a cleartext transmission vulnerability in Rubetek RV-3406, RV-3409, and RV-3411 cameras. The vulnerability allows interception and modification of video data, NTP, and RTSP responses due to unencrypted transmission.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Theoretical
Target: Rubetek RV-3406, RV-3409, RV-3411 (firmware v339, v342)
No auth needed
Prerequisites: Man-in-the-middle position on the network
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://github.com/jet-pentest/CVE-2020-25748

Scores

CVSS v3 8.1
EPSS 0.0083
EPSS Percentile 52.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-319
Status published
Products (6)
rubetek/rv-3406_firmware 339
rubetek/rv-3406_firmware 342
rubetek/rv-3409_firmware 339
rubetek/rv-3409_firmware 342
rubetek/rv-3411_firmware 339
rubetek/rv-3411_firmware 342
Published Sep 25, 2020
Tracked Since Feb 18, 2026