Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 29 Oct 2024 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 29 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863

Tue, 10 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Shenzhen Haichangxing Technology
Shenzhen Haichangxing Technology hcx H822 Firmware
Weaknesses CWE-284
CPEs cpe:2.3:o:shenzhen_haichangxing_technology:hcx_h822_firmware:m7628nnxispxuiv2_v1.0.1557.15.35_p0:*:*:*:*:*:*:*
Vendors & Products Shenzhen Haichangxing Technology
Shenzhen Haichangxing Technology hcx H822 Firmware
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 16:45:00 +0000

Type Values Removed Values Added
Description Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-29T16:04:11.858Z

Reserved: 2024-08-21T00:00:00

Link: CVE-2024-44667

cve-icon Vulnrichment

Updated: 2024-09-10T20:06:21.801Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-10T17:15:37.030

Modified: 2024-10-29T16:35:13.953

Link: CVE-2024-44667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.