CVE-2017-14335
PoC —CVSS 3.0
7.5 high
EPSS
28%p98
Published
()
Modified
Description
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
- Vendors
- hbgk
- Products
- hb7024xt firmware, hb7032xt firmware, hb7008t2 firmware, hb7016t2 firmware, hb7204xt firmware, hb7208xt firmware, hb7216xt firmware, hb7208x3 firmware, hb7216x3 firmware, hb7204x firmware, hb7208x firmware, hb7216x firmware
- Weakness
- CWE-20
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.