CVE-2020-8964: Timetoolsltd SC7105 Firmware

Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.

TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."

Affected products

Published 2020-02-13. Last modified 2026-06-17.