Rubetek manufactures a focused line of IP-based security and surveillance devices, including its RV-series network cameras and recorders, which present a concentrated attack surface around embedded network infrastructure. The recurring vulnerability surface centers on authentication and cryptographic handling—cleartext transmission of sensitive data, missing authentication controls on critical functions, and hard-coded credentials—reflecting the access-control and secure-communication demands of remotely managed surveillance appliances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rubetek over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9550CRITICAL Rubetek SmartHome 2020 devices use unencrypted 433 MHz communication between controllers and beacons, allowing an attacker to sniff and spoof beacon requests remotely. | Mar 4, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-25749CRITICAL The Telnet service of Rubetek cameras RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) could allow an remote attacker to take full control of the device with a | Sep 25, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-25747CRITICAL The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without aut | Sep 25, 2020 | 9.4 | 27 | NO | NO |
CVE-2020-25748HIGH A Cleartext Transmission issue was discovered on Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339). Someone in the middle can intercept and modify the vi | Sep 25, 2020 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rubetek.
Media articles that mention a CVE ID that affects a product developed by Rubetek — matched by CVE ID, not by vendor name.