CVE-2017-7912

CRITICAL

Hanwhasecurity Srn-4000 Firmware - Improper Access Control

Title source: rule

Description

Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could allow an attacker to gain access to the device management page with admin privileges without proper authentication.

Scores

CVSS v3 9.8
EPSS 0.0065
EPSS Percentile 70.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284 CWE-287
Status published
Products (1)
hanwhasecurity/srn-4000_firmware < 2.16_170401
Published Apr 08, 2019
Tracked Since Feb 18, 2026