7.5

CVE-2017-14335

Exploit
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HbgkHb7024xt Firmware Version-
   HbgkHb7024xt Version-
HbgkHb7032xt Firmware Version-
   HbgkHb7032xt Version-
HbgkHb7008t2 Firmware Version-
   HbgkHb7008t2 Version-
HbgkHb7016t2 Firmware Version-
   HbgkHb7016t2 Version-
HbgkHb7204xt Firmware Version-
   HbgkHb7204xt Version-
HbgkHb7208xt Firmware Version-
   HbgkHb7208xt Version-
HbgkHb7216xt Firmware Version-
   HbgkHb7216xt Version-
HbgkHb7208x3 Firmware Version-
   HbgkHb7208x3 Version-
HbgkHb7216x3 Firmware Version-
   HbgkHb7216x3 Version-
HbgkHb7204x Firmware Version-
   HbgkHb7204x Version-
HbgkHb7208x Firmware Version-
   HbgkHb7208x Version-
HbgkHb7216x Firmware Version-
   HbgkHb7216x Version-
Hbgk7204xr Firmware Version-
   Hbgk7204xr Version-
Hbgk7208xr Firmware Version-
   Hbgk7208xr Version-
Hbgk7216xr Firmware Version-
   Hbgk7216xr Version-
HbgkHb7004k Firmware Version-
   HbgkHb7004k Version-
HbgkHb7004kh Firmware Version-
   HbgkHb7004kh Version-
HbgkHb7008kc Firmware Version-
   HbgkHb7008kc Version-
HbgkHb7008kce Firmware Version-
   HbgkHb7008kce Version-
HbgkHb7008kh Firmware Version-
   HbgkHb7008kh Version-
HbgkHb7008khe Firmware Version-
   HbgkHb7008khe Version-
HbgkHb7204kl Firmware Version-
   HbgkHb7204kl Version-
HbgkHb7204kk Firmware Version-
   HbgkHb7204kk Version-
HbgkHb7016lc Firmware Version-
   HbgkHb7016lc Version-
HbgkHb7016lh Firmware Version-
   HbgkHb7016lh Version-
HbgkHb7116x3 Firmware Version-
   HbgkHb7116x3 Version-
HbgkHb7108x3 Firmware Version-
   HbgkHb7108x3 Version-
HbgkHb8004 Firmware Version-
   HbgkHb8004 Version-
HbgkHb8008 Firmware Version-
   HbgkHb8008 Version-
HbgkHb8016 Firmware Version-
   HbgkHb8016 Version-
HbgkHb8004r Firmware Version-
   HbgkHb8004r Version-
HbgkHb8008r Firmware Version-
   HbgkHb8008r Version-
HbgkHb8016r Firmware Version-
   HbgkHb8016r Version-
HbgkHb8204h Firmware Version-
   HbgkHb8204h Version-
HbgkHb8208h Firmware Version-
   HbgkHb8208h Version-
HbgkHb8216h Firmware Version-
   HbgkHb8216h Version-
HbgkHb8204hr Firmware Version-
   HbgkHb8204hr Version-
HbgkHb8208hr Firmware Version-
   HbgkHb8208hr Version-
HbgkHb8216hr Firmware Version-
   HbgkHb8216hr Version-
HbgkHb8208x3 Firmware Version-
   HbgkHb8208x3 Version-
HbgkHb8216x3 Firmware Version-
   HbgkHb8216x3 Version-
HbgkHb8608x3 Firmware Version-
   HbgkHb8608x3 Version-
HbgkHb8616x3 Firmware Version-
   HbgkHb8616x3 Version-
HbgkHb8808x3 Firmware Version-
   HbgkHb8808x3 Version-
HbgkHb8816x3 Firmware Version-
   HbgkHb8816x3 Version-
HbgkHb9404x3 Firmware Version-
   HbgkHb9404x3 Version-
HbgkHb9408x3 Firmware Version-
   HbgkHb9408x3 Version-
HbgkHb9604x3 Firmware Version-
   HbgkHb9604x3 Version-
HbgkHb9608x3 Firmware Version-
   HbgkHb9608x3 Version-
HbgkHb9012x3 Firmware Version-
   HbgkHb9012x3 Version-
HbgkHb9020x3 Firmware Version-
   HbgkHb9020x3 Version-
HbgkHb9212x3 Firmware Version-
   HbgkHb9212x3 Version-
HbgkHb9220x3 Firmware Version-
   HbgkHb9220x3 Version-
HbgkHb7904 Firmware Version-
   HbgkHb7904 Version-
HbgkHb7908 Firmware Version-
   HbgkHb7908 Version-
HbgkHb7916s Firmware Version-
   HbgkHb7916s Version-
HbgkHb7904x Firmware Version-
   HbgkHb7904x Version-
HbgkHb7908x Firmware Version-
   HbgkHb7908x Version-
HbgkHb7916sx Firmware Version-
   HbgkHb7916sx Version-
HbgkHb9904 Firmware Version-
   HbgkHb9904 Version-
HbgkHb9908 Firmware Version-
   HbgkHb9908 Version-
HbgkHb9912 Firmware Version-
   HbgkHb9912 Version-
HbgkHb9916 Firmware Version-
   HbgkHb9916 Version-
HbgkHb9924 Firmware Version-
   HbgkHb9924 Version-
HbgkHb9932 Firmware Version-
   HbgkHb9932 Version-
HbgkHb9808n04 Firmware Version-
   HbgkHb9808n04 Version-
HbgkHb9816n08 Firmware Version-
   HbgkHb9816n08 Version-
HbgkHb9824n16 Firmware Version-
   HbgkHb9824n16 Version-
HbgkHb9832n16 Firmware Version-
   HbgkHb9832n16 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 20.18% 0.95
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.