CVE-2021-26705
CRITICALSquarebox Catdv < 9.2 - Missing Authentication
Title source: ruleDescription
An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke administrative tasks within the application, such as disclosing password hashes.
Exploits (1)
exploitdb
WORKING POC
by Christopher Ellis · javaremotejava
https://www.exploit-db.com/exploits/49621
Scores
CVSS v3
9.1
EPSS
0.0048
EPSS Percentile
64.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Classification
CWE
CWE-306
Status
published
Affected Products (1)
squarebox/catdv
< 9.2
Timeline
Published
Mar 05, 2021
Tracked Since
Feb 18, 2026