Record summary

CVE-2021-28151 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 24, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHHongdian H8922 3.0.5 - Remote Command InjectionCVSS 8.8

Hongdian H8922 3.0.5 devices are susceptible to remote command injection via shell metacharacters into the ip-address (a/k/a Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system.

Impact

Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected device.

Remediation

Apply the latest security patch or update to a non-vulnerable version of the Hongdian H8922 firmware.

WeaknessesCWE-78
Authorsgy741
Template tagscve2021cvehongdianrceinjectionvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:hongdian:h8922_firmware:3.0.5:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3