Vulnerability Description
CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cacagoo | Tv-288Zd-2Mp Firmware | 3.4.2.0919 |
| Cacagoo | Tv-288Zd-2Mp | - |
Related Weaknesses (CWE)
References
- https://insights.oem.avira.com/serious-security-flaws-uncovered-in-cacagoo-ip-caExploitThird Party Advisory
- https://www.cacagoo.comProduct
- https://insights.oem.avira.com/serious-security-flaws-uncovered-in-cacagoo-ip-caExploitThird Party Advisory
- https://www.cacagoo.comProduct
FAQ
What is CVE-2020-6852?
CVE-2020-6852 is a vulnerability with a CVSS score of 9.8 (CRITICAL). CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required.
How severe is CVE-2020-6852?
CVE-2020-6852 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-6852?
Check the references section above for vendor advisories and patch information. Affected products include: Cacagoo Tv-288Zd-2Mp Firmware, Cacagoo Tv-288Zd-2Mp.