ZeroHour

CVE-2017-14335

PoC
CVSS 3.0
7.5 high
EPSS
28%p98
Published
()
Modified
Description

On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.

Vendors
hbgk
Products
hb7024xt firmware, hb7032xt firmware, hb7008t2 firmware, hb7016t2 firmware, hb7204xt firmware, hb7208xt firmware, hb7216xt firmware, hb7208x3 firmware, hb7216x3 firmware, hb7204x firmware, hb7208x firmware, hb7216x firmware
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.