Record summary

CVE-2021-28149 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges to download any file from the device by substituting ../ (e.g., ../../etc/passwd) This can be carried out with a web browser by changing the file name accordingly. Upon visiting log_download.cgi?type=../../etc/passwd and logging in, the web server will allow a download of the contents of the /etc/passwd file.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 7, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMHongdian H8922 3.0.5 Devices - Local File InclusionCVSS 6.5

Hongdian H8922 3.0.5 devices are vulnerable to local file inclusion. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges to download any file from the device by substituting ../ (e.g., ../../etc/passwd) This can be carried out with a web browser by changing the file name accordingly. Upon visiting log_download.cgi?type=../../etc/passwd and logging in, the web server will allow a download of the contents of the /etc/passwd file.

Impact

Successful exploitation of this vulnerability can result in unauthorized access to sensitive files, potentially leading to further compromise of the system.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the LFI vulnerability in Hongdian H8922 3.0.5 Devices.

WeaknessesCWE-22
Authorsgy741
Template tagscve2021cvehongdiantraversalvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:hongdian:h8922_firmware:3.0.5:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3