Vulnerability Description
An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote attacker to take full control of the camera with a high-privileged account. The vulnerability exists because a static username and password are compiled into the ppsapp RESTful application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Merkuryinnovations | Geeni Gnc-Cw028 Firmware | 2.7.2 |
| Merkuryinnovations | Geeni Gnc-Cw028 | - |
| Merkuryinnovations | Geeni Gnc-Cw025 Firmware | 2.9.5 |
| Merkuryinnovations | Geeni Gnc-Cw025 | - |
| Merkuryinnovations | Merkury Mi-Cw024 Firmware | 2.9.6 |
| Merkuryinnovations | Merkury Mi-Cw024 | - |
| Merkuryinnovations | Merkury Mi-Cw017 Firmware | 2.9.6 |
| Merkuryinnovations | Merkury Mi-Cw017 | - |
Related Weaknesses (CWE)
References
- https://gist.github.com/tj-oconnor/371d34342c0cc2be015cc89d6dc2bc66ExploitThird Party Advisory
- https://support.mygeeni.com/hc/en-usVendor Advisory
- https://gist.github.com/tj-oconnor/371d34342c0cc2be015cc89d6dc2bc66ExploitThird Party Advisory
- https://support.mygeeni.com/hc/en-usVendor Advisory
FAQ
What is CVE-2020-29001?
CVE-2020-29001 is a vulnerability with a CVSS score of 7.2 (HIGH). An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTf...
How severe is CVE-2020-29001?
CVE-2020-29001 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-29001?
Check the references section above for vendor advisories and patch information. Affected products include: Merkuryinnovations Geeni Gnc-Cw028 Firmware, Merkuryinnovations Geeni Gnc-Cw028, Merkuryinnovations Geeni Gnc-Cw025 Firmware, Merkuryinnovations Geeni Gnc-Cw025, Merkuryinnovations Merkury Mi-Cw024 Firmware.