CVE-2020-8964

TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:timetoolsltd:sr9850_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sr9850:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:timetoolsltd:sr9750_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sr9750:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:timetoolsltd:sc9705_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sc9705:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:timetoolsltd:sr9210_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sr9210:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:timetoolsltd:sc9205_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sc9205:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:timetoolsltd:sr7110_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sr7110:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:timetoolsltd:sc7105_firmware:1.0.007:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:sc7105:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:timetoolsltd:t100_firmware:1.0.003:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:t100:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:timetoolsltd:t300_firmware:1.0.003:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:t300:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:timetoolsltd:t550_firmware:1.0.003:*:*:*:*:*:*:*
cpe:2.3:h:timetoolsltd:t550:-:*:*:*:*:*:*:*

Information

Published : 2020-02-13 03:15

Updated : 2020-02-25 18:01


NVD link : CVE-2020-8964

Mitre link : CVE-2020-8964


JSON object : View

Products Affected

timetoolsltd

  • sc9705_firmware
  • t300_firmware
  • sr9850_firmware
  • sr9750_firmware
  • sc7105_firmware
  • sc9205_firmware
  • sr9210_firmware
  • t550
  • sr7110
  • t100
  • sr9850
  • t100_firmware
  • sc7105
  • sr9750
  • t300
  • t550_firmware
  • sr9210
  • sc9205
  • sc9705
  • sr7110_firmware
CWE
CWE-798

Use of Hard-coded Credentials