Vulnerability Description
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cylan | Clever Dog Smart Camera Panorama Dog-2W Firmware | - |
| Cylan | Clever Dog Smart Camera Panorama Dog-2W | - |
| Cylan | Clever Dog Smart Camera Plus Dog-2W-V4 Firmware | - |
| Cylan | Clever Dog Smart Camera Plus Dog-2W-V4 | - |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/46993Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46993Third Party AdvisoryVDB Entry
FAQ
What is CVE-2019-12920?
CVE-2019-12920 is a vulnerability with a CVSS score of 9.8 (CRITICAL). On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 pas...
How severe is CVE-2019-12920?
CVE-2019-12920 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-12920?
Check the references section above for vendor advisories and patch information. Affected products include: Cylan Clever Dog Smart Camera Panorama Dog-2W Firmware, Cylan Clever Dog Smart Camera Panorama Dog-2W, Cylan Clever Dog Smart Camera Plus Dog-2W-V4 Firmware, Cylan Clever Dog Smart Camera Plus Dog-2W-V4.