Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Hongdian H8922 3.0.5 devices are vulnerable to local file inclusion. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges to download any file from the device by substituting ../ (e.g., ../../etc/passwd) This can be carried out with a web browser by changing the file name accordingly. Upon visiting log_download.cgi?type=../../etc/passwd and logging in, the web server will allow a download of the contents of the /etc/passwd file. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-28149.yaml | POC Details |
| 2 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E7%BD%91%E7%BB%9C%E8%AE%BE%E5%A4%87%E6%BC%8F%E6%B4%9E/%E5%AE%8F%E7%94%B5%20H8922%20Telnet%E5%90%8E%E9%97%A8%E6%BC%8F%E6%B4%9E%20CVE-2021-28149.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-32052 | Django 跨站脚本漏洞 | |
| CVE-2020-23264 | forkcms 跨站请求伪造漏洞 | |
| CVE-2021-28665 | Stormshield Network Security 资源管理错误漏洞 | |
| CVE-2021-27941 | IFTTT eWeLink 安全漏洞 | |
| CVE-2021-29203 | HP Edgeline Infrastructure Management 访问控制错误漏洞 | |
| CVE-2021-31737 | Emlog 代码问题漏洞 | |
| CVE-2020-23263 | Fork CMS 跨站脚本漏洞 | |
| CVE-2019-25043 | ModSecurity 安全漏洞 | |
| CVE-2021-31918 | tripleo-ansible 信息泄露漏洞 | |
| CVE-2021-31916 | Linux kernel 缓冲区错误漏洞 | |
| CVE-2021-31793 | Night Owl WDB-20-V2 访问控制错误漏洞 | |
| CVE-2021-31829 | Linux kernel 安全漏洞 | |
| CVE-2021-3507 | QEMU 缓冲区错误漏洞 | |
| CVE-2021-28150 | Hongdian H8922 输入验证错误漏洞 | |
| CVE-2021-28152 | Hongdian H8922 授权问题漏洞 | |
| CVE-2021-28151 | Hongdian H8922 操作系统命令注入漏洞 | |
| CVE-2021-32030 | ASUS GT-AC2900 授权问题漏洞 | |
| CVE-2021-20204 | Homebrew Formulae libgetdata 缓冲区错误漏洞 | |
| CVE-2020-35519 | Linux kernel 缓冲区错误漏洞 | |
| CVE-2021-28128 | Strapi 授权问题漏洞 |
Showing top 20 of 54 CVEs. View all on vendor page → →
No comments yet