CVE-2020-10207
Summary
| CVE | CVE-2020-10207 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-29 23:15:00 UTC |
| Updated | 2021-01-14 16:07:00 UTC |
| Description | Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows remote attackers to retrieve and modify the device settings. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Amino | Ak45x | - | All | All | All |
| Hardware | Amino | Ak45x | - | All | All | All |
| Operating System | Amino | Ak45x Firmware | - | All | All | All |
| Operating System | Amino | Ak45x Firmware | - | All | All | All |
| Hardware | Amino | Ak5xx | - | All | All | All |
| Hardware | Amino | Ak5xx | - | All | All | All |
| Operating System | Amino | Ak5xx Firmware | - | All | All | All |
| Operating System | Amino | Ak5xx Firmware | - | All | All | All |
| Hardware | Amino | Ak65x | - | All | All | All |
| Hardware | Amino | Ak65x | - | All | All | All |
| Operating System | Amino | Ak65x Firmware | - | All | All | All |
| Operating System | Amino | Ak65x Firmware | - | All | All | All |
| Hardware | Amino | Aria6xx | - | All | All | All |
| Hardware | Amino | Aria6xx | - | All | All | All |
| Operating System | Amino | Aria6xx Firmware | - | All | All | All |
| Operating System | Amino | Aria6xx Firmware | - | All | All | All |
| Hardware | Amino | Aria7xx | - | All | All | All |
| Hardware | Amino | Aria7xx | - | All | All | All |
| Operating System | Amino | Aria7xx Firmware | - | All | All | All |
| Operating System | Amino | Aria7xx Firmware | - | All | All | All |
| Hardware | Amino | Kami7b | - | All | All | All |
| Hardware | Amino | Kami7b | - | All | All | All |
| Operating System | Amino | Kami7b Firmware | - | All | All | All |
| Operating System | Amino | Kami7b Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PWNing my ISPs STBs. Remember that scene from the movie… | by André Oudhof | Medium | MISC | andre-oudhof.medium.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.