CVE-2020-11681: Castel NextGen Dvr Firmware

High severity, CVSS 8.1. EPSS: 1.1% chance of exploitation in the next 30 days.

Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credentials.

Affected products

  • Castel NextGen Dvr Firmware: version 1.0.0 only

Published 2020-06-04. Last modified 2026-06-17.