CRITICAL
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices
Published Jul 22, 2021
9.8
CRITICALCVSS 3.1
EPSS 3.65%
Description
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. The device by default has a TELNET interface available (which is not advertised or functionally used, but is nevertheless available). Two backdoor accounts (root and default) exist that can be used on this interface. The usernames and passwords of the backdoor accounts are the same on all devices. Attackers can use these backdoor accounts to obtain access and execute code as root within the device.
Affected products
No data.
AND
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (4)
- http://seclists.org/fulldisclosure/2024/Jul/14 mailing-list
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11012 Advisory
- https://www.eurofins-cybersecurity.com/news/connected-devices-baby-monitors-part-2/ ExploitThird Party Advisory
- https://www.sannce.com Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2024/Jul/14 | mailing-list | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-11012 | Advisory | |
| https://www.eurofins-cybersecurity.com/news/connected-devices-baby-monitors-part-2/ | ExploitThird Party Advisory | |
| https://www.sannce.com | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 22, 2021
Updated Aug 5, 2024
Reserved Feb 17, 2020
Link CVE-2019-20467
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-11012 Assigner mitre
Published Jul 22, 2021
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-11012