Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI3518_50H10L_S39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.
References
Link | Resource |
---|---|
https://github.com/Snawoot/hisilicon-dvr-telnet | Third Party Advisory |
https://github.com/tothi/hs-dvr-telnet | Third Party Advisory |
https://habr.com/en/post/486856/ | Exploit Third Party Advisory |
https://www.xiongmaitech.com/en/index.php/news/info/12/68 | Vendor Advisory |
https://github.com/Snawoot/hisilicon-dvr-telnet | Third Party Advisory |
https://github.com/tothi/hs-dvr-telnet | Third Party Advisory |
https://habr.com/en/post/486856/ | Exploit Third Party Advisory |
https://www.xiongmaitech.com/en/index.php/news/info/12/68 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
History
No history.
Information
Published : 2022-06-30 13:15
Updated : 2024-11-21 06:26
NVD link : CVE-2021-41506
Mitre link : CVE-2021-41506
CVE.ORG link : CVE-2021-41506
JSON object : View
Products Affected
xiongmaitech
- ahb7804r-lms
- ahb7804r-els_firmware
- hi3518e_50h10l_s39
- ahb7808r-ms-v2
- ahb7808t-ms-v2_firmware
- ahb7808r-ms
- ahb7808r-ms_firmware
- ahb7008t-mh-v2_firmware
- ahb7008t-mh-v2
- ahb7808r-ms-v2_firmware
- hi3518e_50h10l_s39_firmware
- ahb7804r-els
- ahb7804r-mh-v2
- ahb7808t-ms-v2
- ahb7804r-lms_firmware
- ahb7804r-mh-v2_firmware
CWE
CWE-287
Improper Authentication