CVE-2020-8964
9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.66% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-798 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-02-13 |
| Last modified | 2026-06-17 |
Affected (20)
| Vendor | Product |
|---|---|
| timetoolsltd | sc7105 |
| timetoolsltd | sc7105 firmware |
| timetoolsltd | sc9205 |
| timetoolsltd | sc9205 firmware |
| timetoolsltd | sc9705 |
| timetoolsltd | sc9705 firmware |
| timetoolsltd | sr7110 |
| timetoolsltd | sr7110 firmware |
| timetoolsltd | sr9210 |
| timetoolsltd | sr9210 firmware |
| timetoolsltd | sr9750 |
| timetoolsltd | sr9750 firmware |
| timetoolsltd | sr9850 |
| timetoolsltd | sr9850 firmware |
| timetoolsltd | t100 |
| timetoolsltd | t100 firmware |
| timetoolsltd | t300 |
| timetoolsltd | t300 firmware |
| timetoolsltd | t550 |
| timetoolsltd | t550 firmware |
References
→ the Explorer · watch your stack · NVD