CVE-2017-20204 Details
Description
DBLTek GoIP devices (models GoIP 1, 4, 8, 16, and 32) contain an undocumented vendor backdoor in the Telnet administrative interface that allows remote authentication as an undocumented user via a proprietary challenge–response scheme which is fundamentally flawed. Because the challenge response can be computed from the challenge itself, a remote attacker can authenticate without knowledge of a secret and obtain a root shell on the device. This can lead to persistent remote code execution, full device compromise, and arbitrary control of the device and any managed services. The firmware used within these devices was updated in December 2016 to make this vulnerability more complex to exploit. However, it is unknown if DBLTek has taken steps to fully mitigate.
A backdoor vulnerability has been identified in the Telnet administrative interface of DBLTek GoIP devices, specifically models 1, 4, 8, 16, and 32. This vulnerability allows remote authentication as an undocumented user through a flawed challenge-response authentication scheme. The challenge-response mechanism can be exploited to compute the response and gain unauthorized access, leading to a root shell on the device. This exploitation allows for persistent remote code execution, full device compromise, and arbitrary control over the device and its managed services. Although a firmware update was released in December 2016 that aimed to complicate the exploitation of this vulnerability, it remains unclear whether DBLTek has fully addressed the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 15, 2025CISA-ADP
Assessed Oct 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1242 | Inclusion of Undocumented Features or Chicken Bits | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| DBLTek GoIP 1 | All versions |
CPE
Remediation
| |
| DBLTek GoIP 4 | All versions |
CPE
Remediation
| |
| DBLTek GoIP 8 | All versions |
CPE
Remediation
| |
| DBLTek GoIP 16 | All versions |
CPE
Remediation
| |
| DBLTek GoIP 32 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 15, 2025 | New CVE Received | [email protected] |
Volerion