peter bassill · operator
$ cve CVE-2020-25749 JSON

CVE-2020-25749

9.8
CRITICAL · CVSS 3.1 · EPSS 3.1% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.1% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2020-09-25
Last modified2026-06-17

Affected (6)

VendorProduct
rubetekrv-3406
rubetekrv-3406 firmware
rubetekrv-3409
rubetekrv-3409 firmware
rubetekrv-3411
rubetekrv-3411 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD