CVE-2021-47707
COMMAX CVD-Axx DVR Weak Default Credentials Stream Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can exploit this by sending a POST request with the 'passkey' parameter set to '1234', allowing them to access the web control panel.
| CWE | CWE-1392 |
| Vendor | commax co., ltd. |
| Product | commax cvd-axx dvr |
| Published | Dec 9, 2025 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for commax co., ltd. commax cvd-axx dvr
Be the first to know when new unknown vulnerabilities affecting commax co., ltd. commax cvd-axx dvr are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
COMMAX Co., Ltd. / COMMAX CVD-Axx DVR
CVD-AH04 DVR 4.4.1
References
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab