Home/Product/hongdian h8951 4g esp firmware
Product

hongdian h8951 4g esp firmware

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-49262
< 2310271149
The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an a
9.8CRITICAL
CVE-2023-49261
< 2310271149
The "tokenKey" value used in user authorization is visible in the HTML source of the login page.
7.5HIGH
CVE-2023-49260
< 2310271149
An XSS attack can be performed by changing the MOTD banner and pointing the victim to the "terminal_tool.cgi" path. It can be used
6.1MEDIUM
CVE-2023-49259
< 2310271149
The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be gu
7.5HIGH
CVE-2023-49258
< 2310271149
User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS vulnerabili
6.1MEDIUM
CVE-2023-49257
< 2310271149
An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with
8.8HIGH
CVE-2023-49256
< 2310271149
It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static ke
7.5HIGH
CVE-2023-49255
< 2310271149
The router console is accessible without authentication at "data" field, and while a user needs to be logged in order to modify
9.8CRITICAL
CVE-2023-49254
< 2310271149
Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field
8.8HIGH
CVE-2023-49253
< 2310271149
Root user password is hardcoded into the device and cannot be changed in the user interface.
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin