Vulnerability Description
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hbgk | Hb7024Xt Firmware | - |
| Hbgk | Hb7024Xt | - |
| Hbgk | Hb7032Xt Firmware | - |
| Hbgk | Hb7032Xt | - |
| Hbgk | Hb7008T2 Firmware | - |
| Hbgk | Hb7008T2 | - |
| Hbgk | Hb7016T2 Firmware | - |
| Hbgk | Hb7016T2 | - |
| Hbgk | Hb7204Xt Firmware | - |
| Hbgk | Hb7204Xt | - |
| Hbgk | Hb7208Xt Firmware | - |
| Hbgk | Hb7208Xt | - |
| Hbgk | Hb7216Xt Firmware | - |
| Hbgk | Hb7216Xt | - |
| Hbgk | Hb7208X3 Firmware | - |
| Hbgk | Hb7208X3 | - |
| Hbgk | Hb7216X3 Firmware | - |
| Hbgk | Hb7216X3 | - |
| Hbgk | Hb7204X Firmware | - |
| Hbgk | Hb7204X | - |
Related Weaknesses (CWE)
References
- https://blogs.securiteam.com/index.php/archives/3420ExploitThird Party Advisory
- https://blogs.securiteam.com/index.php/archives/3420ExploitThird Party Advisory
FAQ
What is CVE-2017-14335?
CVE-2017-14335 is a vulnerability with a CVSS score of 7.5 (HIGH). On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
How severe is CVE-2017-14335?
CVE-2017-14335 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14335?
Check the references section above for vendor advisories and patch information. Affected products include: Hbgk Hb7024Xt Firmware, Hbgk Hb7024Xt, Hbgk Hb7032Xt Firmware, Hbgk Hb7032Xt, Hbgk Hb7008T2 Firmware.