CVE-2020-36915

7.5

Adtec Digital · Multiple Products

Multiple Adtec Digital products contain hardcoded default credentials in their Linux images, allowing unauthenticated remote access to web, telnet, and SSH interfaces with root-level privileges.

Executive summary

Several Adtec Digital products are vulnerable to unauthenticated remote code execution due to hardcoded default credentials that grant attackers full root access.

Vulnerability

The affected devices utilize hardcoded and default credentials within their Linux operating system images for web, telnet, and SSH access. This flaw allows an unauthenticated remote attacker to gain root access and execute arbitrary system commands.

Business impact

Successful exploitation of this vulnerability results in a total compromise of the affected hardware. Because the default credentials grant root-level access, an attacker can gain complete control over the device, leading to unauthorized data access, system disruption, or the use of the device as a pivot point for further lateral movement within the network. The CVSS score of 7.5 reflects the high impact on system integrity and availability, and the ease of exploitation makes this a significant security risk for broadcast and media infrastructure.

Remediation

Immediate Action: Change all default passwords for the web, telnet, and SSH interfaces immediately. If a firmware update is available from the vendor that removes these credentials, apply it without delay.

Proactive Monitoring: Monitor network traffic for unauthorized SSH or telnet connections to these devices. Review system logs for command execution patterns or privilege escalation attempts by default user accounts.

Compensating Controls: Isolate vulnerable devices on a restricted management VLAN and use a Web Application Firewall (WAF) or Network Access Control (NAC) to block unauthorized access to management interfaces.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the Exploit-DB entry 48954.

Analyst recommendation

The presence of hardcoded credentials across multiple critical infrastructure products poses a severe risk of unauthorized remote control. Security teams must prioritize identifying any exposed Adtec Digital hardware and restricting network access to management interfaces while password changes are implemented. Given the availability of public exploit code, these devices should be considered high-value targets for attackers seeking to disrupt broadcast or media operations.

Sources

Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.