github.com
https://github.com/Snawoot/hisilicon-dvr-telnet CVE-2021-41506
CRITICAL
xiongmaitech ahb7008t-mh-v2_firmware Improper Authentication
Record summary
CVE-2021-41506 has a selected CVSS score of 9.8 (critical).
Description
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 31, 2019 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ahb7008t-mh-v2_firmwareBrowse xiongmaitech / ahb7008t-mh-v2_firmware | VulnCheck | Version data not supplied | |
References
5github.com
https://github.com/tothi/hs-dvr-telnet habr.com
https://habr.com/en/post/486856 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-41506 xiongmaitech.com
https://www.xiongmaitech.com/en/index.php/news/info/12/68