CVE-2020-25749
CRITICALRubetek RV-3406, RV-3409, RV-3411 Firmware v339, v342 - Use of Hard-coded Credentials in Telnet Service
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-25749. PoCs published by jet-pentest.
AI-analyzed exploit summary This repository contains a writeup describing CVE-2020-25749, a hard-coded credentials vulnerability in Rubetek cameras (RV-3406, RV-3409, RV-3411) running firmware versions v339 and v342. The vulnerability allows remote attackers to gain root access via Telnet using static credentials.
Description
The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.
Exploits (1)
This repository contains a writeup describing CVE-2020-25749, a hard-coded credentials vulnerability in Rubetek cameras (RV-3406, RV-3409, RV-3411) running firmware versions v339 and v342. The vulnerability allows remote attackers to gain root access via Telnet using static credentials.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H