// For flags

CVE-2021-28149

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges to download any file from the device by substituting ../ (e.g., ../../etc/passwd) This can be carried out with a web browser by changing the file name accordingly. Upon visiting log_download.cgi?type=../../etc/passwd and logging in, the web server will allow a download of the contents of the /etc/passwd file.

Los dispositivos Hongdian H8922 versión 3.0.5, permiten un Salto de Directorio. El manejador de exportación de registros /log_download.cgi no comprueba la entrada del usuario y permite a un atacante remoto con privilegios mínimos descargar cualquier archivo del dispositivo sustituyendo ../ (por ejemplo, ../../etc/passwd). con un navegador web cambiando el nombre del archivo en consecuencia. Al visitar log_download.cgi?type=../../etc/passwd e iniciar sesión, el servidor web permitirá una descarga del contenido del archivo /etc/passwd

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-03-11 CVE Reserved
  • 2021-05-06 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • 2024-11-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hongdian
Search vendor "Hongdian"
H8922 Firmware
Search vendor "Hongdian" for product "H8922 Firmware"
3.0.5
Search vendor "Hongdian" for product "H8922 Firmware" and version "3.0.5"
-
Affected
in Hongdian
Search vendor "Hongdian"
H8922
Search vendor "Hongdian" for product "H8922"
--
Safe