CVE-2021-26637

There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:h:shinasys:sihas_sgw-300:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:h:shinasys:sihas_acm-300:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:h:shinasys:sihas_gcm-300:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:56

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 8.8
References () https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66782 - Broken Link, Third Party Advisory, VDB Entry () https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66782 - Broken Link, Third Party Advisory, VDB Entry

26 Jun 2023, 17:49

Type Values Removed Values Added
CWE CWE-287 CWE-306
CWE-862
References (MISC) https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66782 - Third Party Advisory, VDB Entry (MISC) https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66782 - Broken Link, Third Party Advisory, VDB Entry

Information

Published : 2022-06-23 17:15

Updated : 2024-11-21 05:56


NVD link : CVE-2021-26637

Mitre link : CVE-2021-26637

CVE.ORG link : CVE-2021-26637


JSON object : View

Products Affected

shinasys

  • sihas_sgw-300
  • sihas_acm-300_firmware
  • sihas_gcm-300_firmware
  • sihas_sgw-300_firmware
  • sihas_acm-300
  • sihas_gcm-300
CWE
CWE-287

Improper Authentication

CWE-306

Missing Authentication for Critical Function

CWE-862

Missing Authorization