xiongmaitech Vulnerabilities and Affected Products
Vulnerabilities associated with mbd6304t.
Products
Clear product- uc-httpd2 vulnerabilities
- ahb7004t-gs-v3_firmware1 vulnerability
- ahb7004t-mhv2_firmware1 vulnerability
- ahb7008t-mh-v2_firmware1 vulnerability
- ahb7804r-mh-v2_firmware1 vulnerability
- ahb8004t-gl_firmware1 vulnerability
- ahb8008t-gl_firmware1 vulnerability
- ahb8032f-lme_firmware1 vulnerability
- mbd6304t1 vulnerability
- xm530_r80x30-pq_8m_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-45045HIGH | xiongmaitech mbd6304t Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 202… CWE-78Dec 1, 2022 | CVSS8.8v3.1 | EPSS1.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |