Vulnerability Description
KONGTOP DVR devices A303, A403, D303, D305, and D403 contain a backdoor that prints the login password via a Print_Password function call in certain circumstances.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kongtop | D303 Firmware | - |
| Kongtop | D303 | - |
| Kongtop | D305 Firmware | - |
| Kongtop | D305 | - |
| Kongtop | D403 Firmware | - |
| Kongtop | D403 | - |
| Kongtop | A303 Firmware | - |
| Kongtop | A303 | - |
| Kongtop | A403 Firmware | - |
| Kongtop | A403 | - |
Related Weaknesses (CWE)
References
- https://github.com/hucmosin/MyBook/blob/master/KONGTOP_DVR_devices_vulnerabilityThird Party Advisory
- https://github.com/hucmosin/MyBook/blob/master/fu/DVR.pdfThird Party Advisory
- https://github.com/hucmosin/Python_Small_Tool/blob/master/other/DVR_POC.pyExploitThird Party Advisory
- https://github.com/hucmosin/MyBook/blob/master/KONGTOP_DVR_devices_vulnerabilityThird Party Advisory
- https://github.com/hucmosin/MyBook/blob/master/fu/DVR.pdfThird Party Advisory
- https://github.com/hucmosin/Python_Small_Tool/blob/master/other/DVR_POC.pyExploitThird Party Advisory
FAQ
What is CVE-2018-10734?
CVE-2018-10734 is a vulnerability with a CVSS score of 9.8 (CRITICAL). KONGTOP DVR devices A303, A403, D303, D305, and D403 contain a backdoor that prints the login password via a Print_Password function call in certain circumstances.
How severe is CVE-2018-10734?
CVE-2018-10734 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-10734?
Check the references section above for vendor advisories and patch information. Affected products include: Kongtop D303 Firmware, Kongtop D303, Kongtop D305 Firmware, Kongtop D305, Kongtop D403 Firmware.