CVE-2017-14335

On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
References
Link Resource
https://blogs.securiteam.com/index.php/archives/3420 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hbgk:hb7024xt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7024xt:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hbgk:hb7032xt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7032xt:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hbgk:hb7008t2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7008t2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hbgk:hb7016t2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7016t2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hbgk:hb7204xt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7204xt:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hbgk:hb7208xt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7208xt:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hbgk:hb7216xt_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7216xt:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hbgk:hb7208x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7208x3:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hbgk:hb7216x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7216x3:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hbgk:hb7204x_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7204x:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:hbgk:hb7208x_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7208x:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:hbgk:hb7216x_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7216x:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:hbgk:7204xr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:7204xr:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:hbgk:7208xr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:7208xr:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:hbgk:7216xr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:7216xr:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:hbgk:hb7004k_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7004k:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:hbgk:hb7004kh_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7004kh:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:hbgk:hb7008kc_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7008kc:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:hbgk:hb7008kce_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7008kce:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:hbgk:hb7008kh_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7008kh:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:hbgk:hb7008khe_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7008khe:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:hbgk:hb7204kl_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7204kl:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:hbgk:hb7204kk_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7204kk:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:hbgk:hb7016lc_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7016lc:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:hbgk:hb7016lh_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7016lh:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:hbgk:hb7116x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7116x3:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:hbgk:hb7108x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7108x3:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:hbgk:hb8004_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8004:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:hbgk:hb8008_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8008:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:hbgk:hb8016_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8016:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:hbgk:hb8004r_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8004r:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:hbgk:hb8008r_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8008r:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:hbgk:hb8016r_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8016r:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:hbgk:hb8204h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8204h:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:hbgk:hb8208h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8208h:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:hbgk:hb8216h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8216h:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:hbgk:hb8204hr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8204hr:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:hbgk:hb8208hr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8208hr:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:hbgk:hb8216hr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8216hr:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:hbgk:hb8208x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8208x3:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:o:hbgk:hb8216x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8216x3:-:*:*:*:*:*:*:*

Configuration 42 (hide)

AND
cpe:2.3:o:hbgk:hb8608x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8608x3:-:*:*:*:*:*:*:*

Configuration 43 (hide)

AND
cpe:2.3:o:hbgk:hb8616x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8616x3:-:*:*:*:*:*:*:*

Configuration 44 (hide)

AND
cpe:2.3:o:hbgk:hb8808x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8808x3:-:*:*:*:*:*:*:*

Configuration 45 (hide)

AND
cpe:2.3:o:hbgk:hb8816x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb8816x3:-:*:*:*:*:*:*:*

Configuration 46 (hide)

AND
cpe:2.3:o:hbgk:hb9404x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9404x3:-:*:*:*:*:*:*:*

Configuration 47 (hide)

AND
cpe:2.3:o:hbgk:hb9408x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9408x3:-:*:*:*:*:*:*:*

Configuration 48 (hide)

AND
cpe:2.3:o:hbgk:hb9604x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9604x3:-:*:*:*:*:*:*:*

Configuration 49 (hide)

AND
cpe:2.3:o:hbgk:hb9608x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9608x3:-:*:*:*:*:*:*:*

Configuration 50 (hide)

AND
cpe:2.3:o:hbgk:hb9012x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9012x3:-:*:*:*:*:*:*:*

Configuration 51 (hide)

AND
cpe:2.3:o:hbgk:hb9020x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9020x3:-:*:*:*:*:*:*:*

Configuration 52 (hide)

AND
cpe:2.3:o:hbgk:hb9212x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9212x3:-:*:*:*:*:*:*:*

Configuration 53 (hide)

AND
cpe:2.3:o:hbgk:hb9220x3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9220x3:-:*:*:*:*:*:*:*

Configuration 54 (hide)

AND
cpe:2.3:o:hbgk:hb7904_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7904:-:*:*:*:*:*:*:*

Configuration 55 (hide)

AND
cpe:2.3:o:hbgk:hb7908_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7908:-:*:*:*:*:*:*:*

Configuration 56 (hide)

AND
cpe:2.3:o:hbgk:hb7916s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7916s:-:*:*:*:*:*:*:*

Configuration 57 (hide)

AND
cpe:2.3:o:hbgk:hb7904x_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7904x:-:*:*:*:*:*:*:*

Configuration 58 (hide)

AND
cpe:2.3:o:hbgk:hb7908x_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7908x:-:*:*:*:*:*:*:*

Configuration 59 (hide)

AND
cpe:2.3:o:hbgk:hb7916sx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb7916sx:-:*:*:*:*:*:*:*

Configuration 60 (hide)

AND
cpe:2.3:o:hbgk:hb9904_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9904:-:*:*:*:*:*:*:*

Configuration 61 (hide)

AND
cpe:2.3:o:hbgk:hb9908_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9908:-:*:*:*:*:*:*:*

Configuration 62 (hide)

AND
cpe:2.3:o:hbgk:hb9912_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9912:-:*:*:*:*:*:*:*

Configuration 63 (hide)

AND
cpe:2.3:o:hbgk:hb9916_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9916:-:*:*:*:*:*:*:*

Configuration 64 (hide)

AND
cpe:2.3:o:hbgk:hb9924_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9924:-:*:*:*:*:*:*:*

Configuration 65 (hide)

AND
cpe:2.3:o:hbgk:hb9932_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9932:-:*:*:*:*:*:*:*

Configuration 66 (hide)

AND
cpe:2.3:o:hbgk:hb9808n04_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9808n04:-:*:*:*:*:*:*:*

Configuration 67 (hide)

AND
cpe:2.3:o:hbgk:hb9816n08_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9816n08:-:*:*:*:*:*:*:*

Configuration 68 (hide)

AND
cpe:2.3:o:hbgk:hb9824n16_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9824n16:-:*:*:*:*:*:*:*

Configuration 69 (hide)

AND
cpe:2.3:o:hbgk:hb9832n16_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hbgk:hb9832n16:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-09-12 08:29

Updated : 2024-02-28 16:04


NVD link : CVE-2017-14335

Mitre link : CVE-2017-14335

CVE.ORG link : CVE-2017-14335


JSON object : View

Products Affected

hbgk

  • hb8204hr
  • hb7204kk_firmware
  • hb8808x3_firmware
  • hb9604x3
  • hb7908_firmware
  • hb9808n04_firmware
  • hb8204h_firmware
  • hb8208h
  • hb8204hr_firmware
  • hb7208x
  • hb8608x3_firmware
  • hb9912
  • hb8216x3_firmware
  • 7216xr
  • hb7004kh_firmware
  • hb9808n04
  • hb7908x
  • hb7904x_firmware
  • hb9220x3_firmware
  • hb7216x
  • hb7008t2
  • hb7208xt
  • hb8816x3
  • hb7216xt
  • hb7204x
  • hb9908_firmware
  • hb7204x_firmware
  • hb7204xt
  • hb7016t2_firmware
  • hb7916sx_firmware
  • hb7016lc
  • hb7908x_firmware
  • hb7916s
  • hb7116x3
  • hb7008kc
  • hb8008_firmware
  • hb7004k
  • hb7024xt
  • hb9404x3
  • hb7004kh
  • hb9924
  • hb7916sx
  • hb9404x3_firmware
  • 7204xr_firmware
  • hb9916
  • hb8004r
  • hb8204h
  • hb7016lc_firmware
  • hb9832n16
  • hb9908
  • 7208xr
  • hb7008kh_firmware
  • hb8004
  • hb8208hr
  • hb8016r_firmware
  • hb8216hr
  • hb8208x3_firmware
  • hb7008khe
  • hb7032xt_firmware
  • hb8216h
  • hb7216x_firmware
  • hb8608x3
  • hb7904
  • hb9912_firmware
  • hb9824n16_firmware
  • hb9832n16_firmware
  • hb9916_firmware
  • hb8016_firmware
  • hb7208xt_firmware
  • hb7904_firmware
  • hb8008r_firmware
  • hb9608x3
  • hb8208h_firmware
  • hb7008kce_firmware
  • hb9012x3_firmware
  • hb9212x3_firmware
  • hb7016t2
  • hb7024xt_firmware
  • hb7216x3
  • hb8616x3
  • hb9924_firmware
  • hb8004_firmware
  • hb7204kl
  • hb7908
  • 7208xr_firmware
  • hb7016lh_firmware
  • 7204xr
  • hb7108x3
  • hb7004k_firmware
  • hb9408x3
  • hb7032xt
  • hb9608x3_firmware
  • hb7916s_firmware
  • hb9932
  • hb7208x3
  • hb7008khe_firmware
  • 7216xr_firmware
  • hb7008kh
  • hb8616x3_firmware
  • hb9220x3
  • hb8816x3_firmware
  • hb7216xt_firmware
  • hb9824n16
  • hb8016r
  • hb7116x3_firmware
  • hb7208x3_firmware
  • hb7108x3_firmware
  • hb9816n08_firmware
  • hb8008r
  • hb9816n08
  • hb7204kl_firmware
  • hb8008
  • hb9020x3
  • hb7008kce
  • hb7208x_firmware
  • hb8004r_firmware
  • hb7016lh
  • hb9012x3
  • hb9408x3_firmware
  • hb8016
  • hb8208x3
  • hb9604x3_firmware
  • hb9212x3
  • hb7008t2_firmware
  • hb7204kk
  • hb9932_firmware
  • hb7216x3_firmware
  • hb9020x3_firmware
  • hb8208hr_firmware
  • hb7204xt_firmware
  • hb8216x3
  • hb8808x3
  • hb8216h_firmware
  • hb9904
  • hb7904x
  • hb7008kc_firmware
  • hb9904_firmware
  • hb8216hr_firmware
CWE
CWE-20

Improper Input Validation