CVE-2020-25749: Rubetek RV-3406 Firmware

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. The Telnet service cannot be disabled and this password cannot be changed via standard functionality.

Affected products

  • Rubetek RV-3406 Firmware: version 339 only; version 342 only
  • Rubetek RV-3409 Firmware: version 339 only; version 342 only
  • Rubetek RV-3411 Firmware: version 339 only; version 342 only

Published 2020-09-25. Last modified 2026-06-17.