CVE-2017-14335
UnknownEPSS 27.83%
Last modified
CVE-2017-14335 is a vulnerability of currently unknown severity. On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.. EPSS estimates a 27.83% chance of exploitation in the next 30 days.
Description
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hbgk | Hb7024xt Firmware | All versions |
| Hbgk | Hb7032xt Firmware | All versions |
| Hbgk | Hb7008t2 Firmware | All versions |
| Hbgk | Hb7016t2 Firmware | All versions |
| Hbgk | Hb7204xt Firmware | All versions |
| Hbgk | Hb7208xt Firmware | All versions |
| Hbgk | Hb7216xt Firmware | All versions |
| Hbgk | Hb7208x3 Firmware | All versions |
| Hbgk | Hb7216x3 Firmware | All versions |
| Hbgk | Hb7204x Firmware | All versions |
| Hbgk | Hb7208x Firmware | All versions |
| Hbgk | Hb7216x Firmware | All versions |
| Hbgk | 7204xr Firmware | All versions |
| Hbgk | 7208xr Firmware | All versions |
| Hbgk | 7216xr Firmware | All versions |
| Hbgk | Hb7004k Firmware | All versions |
| Hbgk | Hb7004kh Firmware | All versions |
| Hbgk | Hb7008kc Firmware | All versions |
| Hbgk | Hb7008kce Firmware | All versions |
| Hbgk | Hb7008kh Firmware | All versions |
| Hbgk | Hb7008khe Firmware | All versions |
| Hbgk | Hb7204kl Firmware | All versions |
| Hbgk | Hb7204kk Firmware | All versions |
| Hbgk | Hb7016lc Firmware | All versions |
| Hbgk | Hb7016lh Firmware | All versions |
| Hbgk | Hb7116x3 Firmware | All versions |
| Hbgk | Hb7108x3 Firmware | All versions |
| Hbgk | Hb8004 Firmware | All versions |
| Hbgk | Hb8008 Firmware | All versions |
| Hbgk | Hb8016 Firmware | All versions |
| Hbgk | Hb8004r Firmware | All versions |
| Hbgk | Hb8008r Firmware | All versions |
| Hbgk | Hb8016r Firmware | All versions |
| Hbgk | Hb8204h Firmware | All versions |
| Hbgk | Hb8208h Firmware | All versions |
| Hbgk | Hb8216h Firmware | All versions |
| Hbgk | Hb8204hr Firmware | All versions |
| Hbgk | Hb8208hr Firmware | All versions |
| Hbgk | Hb8216hr Firmware | All versions |
| Hbgk | Hb8208x3 Firmware | All versions |
| Hbgk | Hb8216x3 Firmware | All versions |
| Hbgk | Hb8608x3 Firmware | All versions |
| Hbgk | Hb8616x3 Firmware | All versions |
| Hbgk | Hb8808x3 Firmware | All versions |
| Hbgk | Hb8816x3 Firmware | All versions |
| Hbgk | Hb9404x3 Firmware | All versions |
| Hbgk | Hb9408x3 Firmware | All versions |
| Hbgk | Hb9604x3 Firmware | All versions |
| Hbgk | Hb9608x3 Firmware | All versions |
| Hbgk | Hb9012x3 Firmware | All versions |
Showing 50 of 69 affected configurations. See NVD for the full list.
References
- https://blogs.securiteam.com/index.php/archives/3420Exploit, Third Party Advisory
- https://blogs.securiteam.com/index.php/archives/3420Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14335?
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
How severe is CVE-2017-14335?
Severity scoring for CVE-2017-14335 is pending analysis. The EPSS model estimates a 27.83% probability of exploitation in the next 30 days.
How do I fix CVE-2017-14335?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2017-14335?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
