Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2020-8964 Details
Description
TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi request, aka a "hardcoded cookie."
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sku11army.blogspot.com/2020/02/timetools-sr-sc-series-network-time.html | CVE | ExploitVendor Advisory |
| https://sku11army.blogspot.com/2020/02/timetools-sr-sc-series-network-time.html | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| timetoolsltd sr9850 firmware | 1.0.007 |
CPE
Remediation
| |
| timetoolsltd sr9850 | All versions |
CPE
Remediation
| |
| timetoolsltd sr9750 firmware | 1.0.007 |
CPE
Remediation
| |
| timetoolsltd sr9750 | All versions |
CPE
Remediation
| |
| timetoolsltd sc9705 firmware | 1.0.007 |
CPE
Remediation
| |
| timetoolsltd sc9705 | All versions |
CPE
Remediation
| |
| timetoolsltd sr9210 firmware | 1.0.007 |
CPE
Remediation
| |
| timetoolsltd sr9210 | All versions |
CPE
Remediation
| |
| timetoolsltd sc9205 firmware | 1.0.007 |
CPE
Remediation
| |
| timetoolsltd sc9205 | All versions |
CPE
Remediation
| |
| timetoolsltd sr7110 firmware | 1.0.007 |
CPE
Remediation
| |
| timetoolsltd sr7110 | All versions |
CPE
Remediation
| |
| timetoolsltd sc7105 firmware | 1.0.007 |
CPE
Remediation
| |
| timetoolsltd sc7105 | All versions |
CPE
Remediation
| |
| timetoolsltd t100 firmware | 1.0.003 |
CPE
Remediation
| |
| timetoolsltd t100 | All versions |
CPE
Remediation
| |
| timetoolsltd t300 firmware | 1.0.003 |
CPE
Remediation
| |
| timetoolsltd t300 | All versions |
CPE
Remediation
| |
| timetoolsltd t550 firmware | 1.0.003 |
CPE
Remediation
| |
| timetoolsltd t550 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 25, 2020 | Initial Analysis | [email protected] |