CVE-2020-9526

MEDIUM

CS2 Network P2P < 3.0.3a - Cleartext Transmission of Sensitive Information

Title source: llm
STIX 2.1

Description

CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the network, as demonstrated by passively eavesdropping on user video/audio streams, capturing credentials, and compromising devices.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://hacked.camera/
Third Party Advisory x_refsource_misc
https://redprocyon.com

Scores

CVSS v3 5.9
EPSS 0.0060
EPSS Percentile 44.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-319 CWE-327
Status published
Products (1)
cs2-network/p2p < 3.0.3a
Published Aug 10, 2020
Tracked Since Feb 18, 2026