CVE-2020-26097: Planet NVR-1615 Firmware

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing telnet on the Internet, remote root access on the device is possible. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Affected products

  • Planet NVR-1615 Firmware: affected versions not specified
  • Planet NVR-915 Firmware: affected versions not specified

Published 2020-11-18. Last modified 2026-06-17.