peter bassill · operator
$ cve CVE-2020-8964 JSON

CVE-2020-8964

9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.66% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2020-02-13
Last modified2026-06-17

Affected (20)

VendorProduct
timetoolsltdsc7105
timetoolsltdsc7105 firmware
timetoolsltdsc9205
timetoolsltdsc9205 firmware
timetoolsltdsc9705
timetoolsltdsc9705 firmware
timetoolsltdsr7110
timetoolsltdsr7110 firmware
timetoolsltdsr9210
timetoolsltdsr9210 firmware
timetoolsltdsr9750
timetoolsltdsr9750 firmware
timetoolsltdsr9850
timetoolsltdsr9850 firmware
timetoolsltdt100
timetoolsltdt100 firmware
timetoolsltdt300
timetoolsltdt300 firmware
timetoolsltdt550
timetoolsltdt550 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD