peter bassill · operator
$ cve CVE-2017-14335 JSON

CVE-2017-14335 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 27.8% (pctl 98)

Patch early

A public exploit exists.

Description

On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS27.83% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2017-09-12
Last modified2026-06-17

Affected (40)

VendorProduct
hbgk7204xr
hbgk7204xr firmware
hbgk7208xr
hbgk7208xr firmware
hbgk7216xr
hbgk7216xr firmware
hbgkhb7004k
hbgkhb7004k firmware
hbgkhb7004kh
hbgkhb7004kh firmware
hbgkhb7008kc
hbgkhb7008kc firmware
hbgkhb7008kce
hbgkhb7008kce firmware
hbgkhb7008kh
hbgkhb7008kh firmware
hbgkhb7008t2
hbgkhb7008t2 firmware
hbgkhb7016t2
hbgkhb7016t2 firmware
hbgkhb7024xt
hbgkhb7024xt firmware
hbgkhb7032xt
hbgkhb7032xt firmware
hbgkhb7204x
hbgkhb7204x firmware
hbgkhb7204xt
hbgkhb7204xt firmware
hbgkhb7208x
hbgkhb7208x firmware
hbgkhb7208x3
hbgkhb7208x3 firmware
hbgkhb7208xt
hbgkhb7208xt firmware
hbgkhb7216x
hbgkhb7216x firmware
hbgkhb7216x3
hbgkhb7216x3 firmware
hbgkhb7216xt
hbgkhb7216xt firmware

Public exploits

SourceTitleDate
exploit-dbHanbanggaoke IP Camera - Arbitrary Password Change2017-09-11

References

→ the Explorer  ·  watch your stack  ·  NVD