Showing 4 vulnerabilities on this page for h8922

Signals CISA KEV Ransomware Nuclei
Hongdian vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

hongdian h8922 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges to download any file from the device by substituting ../ (e.g., ../../etc/passwd) This can be carried out with a web browser by changing the file name accordingly. Upon visiting log_download.cgi?type=../../etc/passwd and logging in, the web server will allow a download of the contents of the /etc/passwd file.

CWE-22May 6, 20211 related artifact
CVSS6.5v3.1EPSS15.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

hongdian h8922 Direct Request ('Forced Browsing')

Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via /backup2.cgi.

CWE-20CWE-425May 6, 20211 related artifact
CVSS5.5v3.1EPSS2.79%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

hongdian h8922 Improper Authentication

Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the telnet service is used on port 5188 with the default credentials of root:superzxmn.

CWE-287CWE-798May 6, 2021
CVSS9.8v3.1EPSS5.19%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

hongdian h8922 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest.

CWE-78May 6, 20211 related artifact
CVSS8.8v3.1EPSS27.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX