CVE-2020-26097: Critical severity planet nvr-915 firmware vulnerability
UNSUPPORTED WHEN ASSIGNED The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing telnet on the Internet, remote root access on the device is possible. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26097?
CVE-2020-26097 has a high severity due to the potential for remote root access through default credentials.
How do I fix CVE-2020-26097?
To mitigate CVE-2020-26097, update the firmware of the affected PLANET NVR devices to the version released after 2020-10-28.
Which devices are affected by CVE-2020-26097?
CVE-2020-26097 specifically affects PLANET Technology Corp NVR-915 and NVR-1615 devices with firmware versions prior to 2020-10-28.
What risks does CVE-2020-26097 pose if not addressed?
If not addressed, CVE-2020-26097 poses significant security risks including unauthorized remote control of the video recorder.
Are there any workarounds for CVE-2020-26097?
As a workaround for CVE-2020-26097, disabling the telnet service or implementing IP whitelisting can help reduce exposure.