Critical severity9.8NVD Advisory· Published Dec 29, 2020· Updated Jun 17, 2026
CVE-2020-10207
CVE-2020-10207
Description
Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows remote attackers to retrieve and modify the device settings.
Affected products
11- cpe:2.3:o:amino:ak45x_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:amino:ak5xx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:amino:ak65x_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:amino:aria6xx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:amino:aria7xx_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:amino:kami7b_firmware:-:*:*:*:*:*:*:*
- Amino Communications/AK45x seriesdescription
Patches
Vulnerability mechanics
References
1- andre-oudhof.medium.com/pwning-my-isps-stbs-c5e78544274dnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.