Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.
References
Link | Resource |
---|---|
https://github.com/Snawoot/hisilicon-dvr-telnet | Third Party Advisory |
https://github.com/tothi/hs-dvr-telnet | Third Party Advisory |
https://habr.com/en/post/486856/ | Exploit Third Party Advisory |
https://www.xiongmaitech.com/en/index.php/news/info/12/68 | Vendor Advisory |
https://github.com/Snawoot/hisilicon-dvr-telnet | Third Party Advisory |
https://github.com/tothi/hs-dvr-telnet | Third Party Advisory |
https://habr.com/en/post/486856/ | Exploit Third Party Advisory |
https://www.xiongmaitech.com/en/index.php/news/info/12/68 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
History
21 Nov 2024, 06:26
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Snawoot/hisilicon-dvr-telnet - Third Party Advisory | |
References | () https://github.com/tothi/hs-dvr-telnet - Third Party Advisory | |
References | () https://habr.com/en/post/486856/ - Exploit, Third Party Advisory | |
References | () https://www.xiongmaitech.com/en/index.php/news/info/12/68 - Vendor Advisory |
08 Aug 2023, 14:22
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-287 |
13 Jul 2022, 17:08
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-522 | |
CVSS |
v2 : v3 : |
v2 : 10.0
v3 : 9.8 |
References | (MISC) https://github.com/Snawoot/hisilicon-dvr-telnet - Third Party Advisory | |
References | (MISC) https://habr.com/en/post/486856/ - Exploit, Third Party Advisory | |
References | (MISC) https://github.com/tothi/hs-dvr-telnet - Third Party Advisory | |
References | (MISC) https://www.xiongmaitech.com/en/index.php/news/info/12/68 - Vendor Advisory | |
CPE | cpe:2.3:o:xiongmaitech:ahb7804r-els_firmware:4.02.r11.nat.onvif.20160422:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb7008t-mh-v2:-:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:ahb7008t-mh-v2_firmware:4.02.r11.7601.nat.onvif.20170420:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb7808r-ms:-:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb7808t-ms-v2:-:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:hi3518e_50h10l_s39:-:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:hi3518e_50h10l_s39_firmware:4.02.r12.nat.onvifs.20170727:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb7804r-els:-:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:ahb7804r-lms_firmware:4.02.r11.nat.20170301:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:ahb7808r-ms_firmware:4.02.r11.nat.onvif.20160328:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:ahb7804r-mh-v2_firmware:4.02.r11.7601.nat.onvif.20170424:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb7808r-ms-v2:-:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb7804r-lms:-:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:ahb7808r-ms-v2_firmware:4.02.r11.nat.onvif.20170327:*:*:*:*:*:*:* cpe:2.3:h:xiongmaitech:ahb7804r-mh-v2:-:*:*:*:*:*:*:* cpe:2.3:o:xiongmaitech:ahb7808t-ms-v2_firmware:4.02.r11.nat.onvifc.20161205:*:*:*:*:*:*:* |
30 Jun 2022, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-06-30 13:15
Updated : 2024-11-21 06:26
NVD link : CVE-2021-41506
Mitre link : CVE-2021-41506
CVE.ORG link : CVE-2021-41506
JSON object : View
Products Affected
xiongmaitech
- ahb7808t-ms-v2
- ahb7008t-mh-v2
- ahb7808r-ms
- ahb7804r-mh-v2
- ahb7804r-lms
- ahb7808t-ms-v2_firmware
- ahb7804r-lms_firmware
- ahb7808r-ms_firmware
- ahb7808r-ms-v2_firmware
- ahb7008t-mh-v2_firmware
- hi3518e_50h10l_s39_firmware
- ahb7804r-els_firmware
- ahb7804r-mh-v2_firmware
- ahb7808r-ms-v2
- ahb7804r-els
- hi3518e_50h10l_s39
CWE
CWE-287
Improper Authentication