CVE-2017-14335
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
12/09/2017
Last modified:
20/04/2025
Description
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:hbgk:hb7024xt_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hbgk:hb7024xt:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hbgk:hb7032xt_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hbgk:hb7032xt:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hbgk:hb7008t2_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hbgk:hb7008t2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hbgk:hb7016t2_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hbgk:hb7016t2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hbgk:hb7204xt_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hbgk:hb7204xt:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hbgk:hb7208xt_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hbgk:hb7208xt:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hbgk:hb7216xt_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hbgk:hb7216xt:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:hbgk:hb7208x3_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



