Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpc6-hwvp-975x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, the attacker can watch live streams from the camera, rotate the camera, change some settings (brightness, clarity, time), restart the camera, or reset it to factory settings.

The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, the attacker can watch live streams from the camera, rotate the camera, change some settings (brightness, clarity, time), restart the camera, or reset it to factory settings.

EPSS

Процентиль: 84%
0.02151
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.4
nvd
больше 5 лет назад

The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, the attacker can watch live streams from the camera, rotate the camera, change some settings (brightness, clarity, time), restart the camera, or reset it to factory settings.

CVSS3: 9.4
fstec
больше 5 лет назад

Уязвимость cлужбы telnet микропрограммного обеспечения Wi-Fi камер Rubetek RV-3406, RV-3409 и RV-3411, позволяющая нарушителю получить несанкционированный доступ к службам RTSP и ONFIV

EPSS

Процентиль: 84%
0.02151
Низкий

Дефекты

CWE-287