CVE-2020-8964

CRITICAL

TimeTools SR/SC/T Series Firmware - Unauthenticated Authentication Bypass via Hardcoded Cookie

Title source: llm
STIX 2.1

Description

TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0366
EPSS Percentile 88.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (10)
timetoolsltd/sc7105_firmware 1.0.007
timetoolsltd/sc9205_firmware 1.0.007
timetoolsltd/sc9705_firmware 1.0.007
timetoolsltd/sr7110_firmware 1.0.007
timetoolsltd/sr9210_firmware 1.0.007
timetoolsltd/sr9750_firmware 1.0.007
timetoolsltd/sr9850_firmware 1.0.007
timetoolsltd/t100_firmware 1.0.003
timetoolsltd/t300_firmware 1.0.003
timetoolsltd/t550_firmware 1.0.003
Published Feb 13, 2020
Tracked Since Feb 18, 2026