CVE-2020-6852
CRITICALCACAGOO TV-288ZD-2MP Firmware 3.4.2.0919 - Unauthenticated Root Access via TELNET
Title source: llmDescription
CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required.
References (2)
Core 2
Core References
Product x_refsource_misc
https://www.cacagoo.com
Exploit, Third Party Advisory x_refsource_misc
https://insights.oem.avira.com/serious-security-flaws-uncovered-in-cacagoo-ip-cameras/
Scores
CVSS v3
9.8
EPSS
0.0236
EPSS Percentile
81.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-307
Status
published
Products (1)
cacagoo/tv-288zd-2mp_firmware
3.4.2.0919
Published
Apr 02, 2020
Tracked Since
Feb 18, 2026