CVE-2017-14335

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
12/09/2017
Last modified:
20/04/2025

Description

On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hbgk:hb7024xt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7024xt:-:*:*:*:*:*:*:*
cpe:2.3:o:hbgk:hb7032xt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7032xt:-:*:*:*:*:*:*:*
cpe:2.3:o:hbgk:hb7008t2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7008t2:-:*:*:*:*:*:*:*
cpe:2.3:o:hbgk:hb7016t2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7016t2:-:*:*:*:*:*:*:*
cpe:2.3:o:hbgk:hb7204xt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7204xt:-:*:*:*:*:*:*:*
cpe:2.3:o:hbgk:hb7208xt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7208xt:-:*:*:*:*:*:*:*
cpe:2.3:o:hbgk:hb7216xt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7216xt:-:*:*:*:*:*:*:*
cpe:2.3:o:hbgk:hb7208x3_firmware:-:*:*:*:*:*:*:*