CVE-2020-29001 Details
Description
An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote attacker to take full control of the camera with a high-privileged account. The vulnerability exists because a static username and password are compiled into the ppsapp RESTful application.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/tj-oconnor/371d34342c0cc2be015cc89d6dc2bc66 | CVE | ExploitThird Party Advisory |
| https://support.mygeeni.com/hc/en-us | CVE | Vendor Advisory |
| https://gist.github.com/tj-oconnor/371d34342c0cc2be015cc89d6dc2bc66 | [email protected] | ExploitThird Party Advisory |
| https://support.mygeeni.com/hc/en-us | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| merkuryinnovations geeni gnc-cw028 firmware | 2.7.2 |
CPE
Remediation
| |
| merkuryinnovations geeni gnc-cw028 | All versions |
CPE
Remediation
| |
| merkuryinnovations geeni gnc-cw025 firmware | 2.9.5 |
CPE
Remediation
| |
| merkuryinnovations geeni gnc-cw025 | All versions |
CPE
Remediation
| |
| merkuryinnovations merkury mi-cw024 firmware | 2.9.6 |
CPE
Remediation
| |
| merkuryinnovations merkury mi-cw024 | All versions |
CPE
Remediation
| |
| merkuryinnovations merkury mi-cw017 firmware | 2.9.6 |
CPE
Remediation
| |
| merkuryinnovations merkury mi-cw017 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 3, 2021 | Initial Analysis | [email protected] |