go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

TONNET DVR - Broken Access Control

TVN ID TVN-201910003
CVE ID CVE-2020-3923
CVSS 8.1 (High)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products TONNET DVR prior to ver. 20191216 in TAT-76 series
TONNET DVR prior to ver. 20200213 in TAT-77 series
Description DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET, contain misconfigured authentication mechanism. Attackers can crack the default password and gain access to the system.
Solution Update to ver. 20191216 in TAT-76 series
Update to ver. 20200213 in TAT-77 series
Credit Weber Tsai (CHT Security)
Public Date 2020-02-21
Top