CVE-2021-33822
Last modified
CVE-2021-33822 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered on 4GEE ROUTER HH70VB Version HH70_E1_02.00_22. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
An issue was discovered on 4GEE ROUTER HH70VB Version HH70_E1_02.00_22. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sing4g | 4gee Router Hh70vb Firmware | hh70_e1_02.00_22 |
References
- https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33822.mdExploit, Third Party Advisory
- https://github.com/shekyan/slowhttptestThird Party Advisory
- https://www.sing4g.com/product-page/4gee-router-hh70vb-4g-300mbps-2lan-32wifiProduct, Vendor Advisory
- https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33822.mdExploit, Third Party Advisory
- https://github.com/shekyan/slowhttptestThird Party Advisory
- https://www.sing4g.com/product-page/4gee-router-hh70vb-4g-300mbps-2lan-32wifiProduct, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33822?
How severe is CVE-2021-33822?
How do I fix CVE-2021-33822?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-33813An XXE issue in SAXBuilder in JDOM through 2.0.6 allows atta…7.5
- CVE-2021-33815dwa_uncompress in libavcodec/exr.c in FFmpeg 4.4 allows an o…8.8
- CVE-2021-33816The website builder module in Dolibarr 13.0.2 allows remote …9.8
- CVE-2021-33818An issue was discovered in UniFi Protect G3 FLEX Camera Vers…7.5
- CVE-2021-3382Stack buffer overflow vulnerability in gitea 1.9.0 through 1…7.5
- CVE-2021-33820An issue was discovered in UniFi Protect G3 FLEX Camera Vers…7.5
- CVE-2021-33823An issue was discovered on MOXA Mgate MB3180 Version 2.1 Bui…7.5
- CVE-2021-33824An issue was discovered on MOXA Mgate MB3180 Version 2.1 Bui…7.5
- CVE-2021-33827The files_antivirus component before 1.0.0 for ownCloud allo…7.2
- CVE-2021-33828The files_antivirus component before 1.0.0 for ownCloud mish…8.8
- CVE-2021-33829A cross-site scripting (XSS) vulnerability in the HTML Data …6.1
- CVE-2021-33831api/account/register in the TH Wildau COVID-19 Contact Traci…6.5
Are you affected by CVE-2021-33822?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
