peter bassill · operator
$ cve CVE-2019-20467 JSON

CVE-2019-20467

9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. The device by default has a TELNET interface available (which is not advertised or functionally used, but is nevertheless available). Two backdoor accounts (root and default) exist that can be used on this interface. The usernames and passwords of the backdoor accounts are the same on all devices. Attackers can use these backdoor accounts to obtain access and execute code as root within the device.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.65% — more likely to be exploited than 89% of all CVEs
On CISA KEVno
Public exploitnone known
Published2021-07-22
Last modified2026-06-17

Affected (2)

VendorProduct
sanncesmart hd wifi security camera ean 2 950004 595317
sanncesmart hd wifi security camera ean 2 950004 595317 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD