CVE-2021-26705

CRITICAL

Squarebox Catdv < 9.2 - Missing Authentication

Title source: rule

Description

An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke administrative tasks within the application, such as disclosing password hashes.

Exploits (1)

exploitdb WORKING POC
by Christopher Ellis · javaremotejava
https://www.exploit-db.com/exploits/49621

Scores

CVSS v3 9.1
EPSS 0.0048
EPSS Percentile 64.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-306
Status published

Affected Products (1)

squarebox/catdv < 9.2

Timeline

Published Mar 05, 2021
Tracked Since Feb 18, 2026