Hongdian Vulnerabilities and Affected Products
Vulnerabilities associated with h8922.
Products
Clear product- H8951-4G-ESP10 vulnerabilities
- h89224 vulnerabilities
- h8951-4g-esp_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-28149MEDIUM | hongdian h8922 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges to download any file from the device by substituting ../ (e.g., ../../etc/passwd) This can be carried out with a web browser by changing the file name accordingly. Upon visiting log_download.cgi?type=../../etc/passwd and logging in, the web server will allow a download of the contents of the /etc/passwd file. | CVSS6.5v3.1 | EPSS15.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-28150MEDIUM | hongdian h8922 Direct Request ('Forced Browsing')Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via /backup2.cgi. | CVSS5.5v3.1 | EPSS2.79% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-28152CRITICAL | hongdian h8922 Improper AuthenticationHongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the telnet service is used on port 5188 with the default credentials of root:superzxmn. | CVSS9.8v3.1 | EPSS5.19% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28151HIGH | hongdian h8922 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest. | CVSS8.8v3.1 | EPSS27.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |