CVE-2017-20204 describes an undocumented vendor backdoor in DBLTek GoIP devices (models 1, 4, 8, 16, and 32) accessible via the Telnet administrative interface. This critical vulnerability, rated 9.3 CVSS, allows remote attackers to authenticate without credentials due to a flawed challenge-response scheme, leading to a root shell. This enables persistent remote code execution, full device compromise, and arbitrary control over the device and its managed services. While a December 2016 firmware update made exploitation more complex, a full mitigation is unconfirmed, and there is no known active exploitation or public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| DBL Technology (DBLTek) | GoIP | All Versions ImpactedCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.