CVE-2020-3923: Tonnet Tat-70432n Firmware

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET, contain misconfigured authentication mechanism. Attackers can crack the default password and gain access to the system.

Affected products

  • Tonnet Tat-70432n Firmware: up to and including tat-77208g1_20181225
  • Tonnet Tat-71416g1 Firmware: up to and including tat-71416g1_20181225
  • Tonnet Tat-71832g1 Firmware: up to and including tat-71832g1_20190510
  • Tonnet Tat-76104g3 Firmware: up to and including 20181220_76104g3
  • Tonnet Tat-76108g3 Firmware: up to and including 20181221_76208g3
  • Tonnet Tat-76116g3 Firmware: up to and including 20181221_76216g3
  • Tonnet Tat-76132g3 Firmware: up to and including tat-70832g3_20181221-1
  • Tonnet Tat-77104g1 Firmware: up to and including tat-77104g1_20190107

Published 2020-02-27. Last modified 2026-06-17.