« Volver al listado

CVE-2020-25747

Estado: ModificadaCrítica (9.4)—💥 PoC

The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, the attacker can watch live streams from the camera, rotate the camera, change some settings (brightness, clarity, time), restart the camera, or reset it to factory settings.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

⚠️ Las pruebas de concepto de GitHub no están verificadas: algunas son falsas o contienen malware. No las ejecute nunca fuera de un laboratorio aislado.

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-25747",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:C",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 8.5,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.4,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-09-25T04:23:05.027",
  "references": [
    {
      "url": "https://github.com/jet-pentest/CVE-2020-25747",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/jet-pentest/CVE-2020-25747",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, the attacker can watch live streams from the camera, rotate the camera, change some settings (brightness, clarity, time), restart the camera, or reset it to factory settings."
    },
    {
      "lang": "es",
      "value": "El servicio Telnet de las cámaras RV-3406, RV-3409 y RV-3411 de Rubetek (versiones de firmware v342, v339), puede permitir a un atacante remoto conseguir acceso a los servicios RTSP y ONFIV sin autenticación. Por lo tanto, el atacante puede ver transmisiones en vivo desde la cámara, girar la cámara, cambiar algunas configuraciones (brillo, claridad, tiempo), reiniciar la cámara o restablecerla a la configuración de fábrica"
    }
  ],
  "lastModified": "2026-06-17T03:07:13.957",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3406_firmware:339:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57AF1900-5D42-45B9-9906-B1EBC933A064"
            },
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3406_firmware:342:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72F51EDA-EA7A-4E58-A071-A0D6F3AEC379"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rubetek:rv-3406:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D0C29138-1CBA-4677-B494-AA5278632606"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3409_firmware:339:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2BD4E56-46E1-4985-A46F-C9B4A374A17F"
            },
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3409_firmware:342:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE539B49-BF73-4411-855D-69E02E6AD917"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rubetek:rv-3409:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "93B04FD1-8EEF-4DDC-83A9-9F5390378D28"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3411_firmware:339:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "183C8C01-1F30-40F5-BD9F-6D217EB1CD42"
            },
            {
              "criteria": "cpe:2.3:o:rubetek:rv-3411_firmware:342:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9ECA3AF-D4F0-4F8B-854C-0C63BB090E44"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:rubetek:rv-3411:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0D54B518-140F-4933-A1C8-45A0A7B3F167"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}