CVE-2023-22906

HIGH

Heroelectronix Qubo Hcd01 Firmware - Missing Authentication

Title source: rule
STIX 2.1

Description

Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.

Exploits (1)

nomisec WORKING POC 8 stars
by nonamecoder · poc
https://github.com/nonamecoder/CVE-2023-22906

References (2)

Core 2
Core References
Exploit, Technical Description, Third Party Advisory
https://github.com/nonamecoder/CVE-2023-22906

Scores

CVSS v3 8.8
EPSS 0.0018
EPSS Percentile 39.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
heroelectronix/qubo_hcd01_firmware 1.38_20220125
heroelectronix/qubo_hcd02_firmware 1.38_20220125
Published Jul 04, 2023
Tracked Since Feb 18, 2026