CRITICAL · 9.8

CVE-2021-41506

Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4...

Vulnerability Description

Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
XiongmaitechAhb7008T-Mh-V2 Firmware4.02.r11.7601.nat.onvif.20170420
XiongmaitechAhb7008T-Mh-V2-
XiongmaitechAhb7804R-Els Firmware4.02.r11.nat.onvif.20160422
XiongmaitechAhb7804R-Els-
XiongmaitechAhb7804R-Mh-V2 Firmware4.02.r11.7601.nat.onvif.20170424
XiongmaitechAhb7804R-Mh-V2-
XiongmaitechAhb7808R-Ms-V2 Firmware4.02.r11.nat.onvif.20170327
XiongmaitechAhb7808R-Ms-V2-
XiongmaitechAhb7808R-Ms Firmware4.02.r11.nat.onvif.20160328
XiongmaitechAhb7808R-Ms-
XiongmaitechAhb7808T-Ms-V2 Firmware4.02.r11.nat.onvifc.20161205
XiongmaitechAhb7808T-Ms-V2-
XiongmaitechAhb7804R-Lms Firmware4.02.r11.nat.20170301
XiongmaitechAhb7804R-Lms-
XiongmaitechHi3518E 50H10L S39 Firmware4.02.r12.nat.onvifs.20170727
XiongmaitechHi3518E 50H10L S39-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-41506?

CVE-2021-41506 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4...

How severe is CVE-2021-41506?

CVE-2021-41506 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-41506?

Check the references section above for vendor advisories and patch information. Affected products include: Xiongmaitech Ahb7008T-Mh-V2 Firmware, Xiongmaitech Ahb7008T-Mh-V2, Xiongmaitech Ahb7804R-Els Firmware, Xiongmaitech Ahb7804R-Els, Xiongmaitech Ahb7804R-Mh-V2 Firmware.