CVE-2020-25747: Rubetek RV-3406 Firmware
Critical severity, CVSS 9.4. EPSS: 1.8% chance of exploitation in the next 30 days.
The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, the attacker can watch live streams from the camera, rotate the camera, change some settings (brightness, clarity, time), restart the camera, or reset it to factory settings.
Affected products
- Rubetek RV-3406 Firmware: version 339 only; version 342 only
- Rubetek RV-3409 Firmware: version 339 only; version 342 only
- Rubetek RV-3411 Firmware: version 339 only; version 342 only
Published 2020-09-25. Last modified 2026-06-17.