CVE-2023-22906

Hero Qubo HCD01_02_V1.38_20220125 devices allow TELNET access with root privileges by default, without a password.
References
Link Resource
https://github.com/nonamecoder/CVE-2023-22906 Exploit Technical Description Third Party Advisory
https://twitter.com/ayyappan162010/status/1610764707753000960 Exploit Third Party Advisory
https://github.com/nonamecoder/CVE-2023-22906 Exploit Technical Description Third Party Advisory
https://twitter.com/ayyappan162010/status/1610764707753000960 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:heroelectronix:qubo_hcd01_firmware:1.38_20220125:*:*:*:*:*:*:*
cpe:2.3:h:heroelectronix:qubo_hcd01:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:heroelectronix:qubo_hcd02_firmware:1.38_20220125:*:*:*:*:*:*:*
cpe:2.3:h:heroelectronix:qubo_hcd02:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:45

Type Values Removed Values Added
References () https://github.com/nonamecoder/CVE-2023-22906 - Exploit, Technical Description, Third Party Advisory () https://github.com/nonamecoder/CVE-2023-22906 - Exploit, Technical Description, Third Party Advisory
References () https://twitter.com/ayyappan162010/status/1610764707753000960 - Exploit, Third Party Advisory () https://twitter.com/ayyappan162010/status/1610764707753000960 - Exploit, Third Party Advisory

10 Jul 2023, 18:02

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CWE CWE-306
CPE cpe:2.3:o:heroelectronix:qubo_hcd02_firmware:1.38_20220125:*:*:*:*:*:*:*
cpe:2.3:o:heroelectronix:qubo_hcd01_firmware:1.38_20220125:*:*:*:*:*:*:*
cpe:2.3:h:heroelectronix:qubo_hcd02:-:*:*:*:*:*:*:*
cpe:2.3:h:heroelectronix:qubo_hcd01:-:*:*:*:*:*:*:*
First Time Heroelectronix qubo Hcd01 Firmware
Heroelectronix qubo Hcd01
Heroelectronix qubo Hcd02
Heroelectronix qubo Hcd02 Firmware
Heroelectronix
References (MISC) https://twitter.com/ayyappan162010/status/1610764707753000960 - (MISC) https://twitter.com/ayyappan162010/status/1610764707753000960 - Exploit, Third Party Advisory
References (MISC) https://github.com/nonamecoder/CVE-2023-22906 - (MISC) https://github.com/nonamecoder/CVE-2023-22906 - Exploit, Technical Description, Third Party Advisory

04 Jul 2023, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-04 00:15

Updated : 2024-11-21 07:45


NVD link : CVE-2023-22906

Mitre link : CVE-2023-22906

CVE.ORG link : CVE-2023-22906


JSON object : View

Products Affected

heroelectronix

  • qubo_hcd02
  • qubo_hcd02_firmware
  • qubo_hcd01
  • qubo_hcd01_firmware
CWE
CWE-306

Missing Authentication for Critical Function