Vulnerability Description
COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access sensitive information, including login credentials and DVR settings, by submitting a GET request to this endpoint.
Related Weaknesses (CWE)
References
- https://www.commax.com
- https://www.exploit-db.com/exploits/50208
- https://www.vulncheck.com/advisories/commax-smart-home-ruvie-cctv-bridge-dvr-ser
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5665.php
FAQ
What is CVE-2021-47710?
CVE-2021-47710 is a documented vulnerability. COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access ...
How severe is CVE-2021-47710?
CVSS scoring is not yet available for CVE-2021-47710. Check NVD for updates.
Is there a patch for CVE-2021-47710?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.