CVE-2021-28151
hongdian h8922 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-28151 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 24, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Nuclei templates
1ProjectDiscoveryHIGHHongdian H8922 3.0.5 - Remote Command InjectionCVSS 8.8
Hongdian H8922 3.0.5 devices are susceptible to remote command injection via shell metacharacters into the ip-address (a/k/a Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system.
Impact
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected device.
Remediation
Apply the latest security patch or update to a non-vulnerable version of the Hongdian H8922 firmware.
Source: ProjectDiscovery