Hongdian Router H8951-4G-ESP是中国宏电(Hongdian)公司的一款无线路由器。 Hongdian Router H8951-4G-ESP 2310271149之前版本存在安全漏洞,该漏洞源于用户授权中使用的“tokenKey”值在登录页面的 HTML 源代码中可见。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hongdian | H8951-4G-ESP | 0 ~ 2310271149 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-49253 | Predefined root password | |
| CVE-2023-49254 | Command injection in the network test tools | |
| CVE-2023-49255 | Router console accessible without authentication | |
| CVE-2023-49256 | Predictable encryption passphrase used in publicly accessible configuration file | |
| CVE-2023-49257 | Command execution using the certificate upload utility | |
| CVE-2023-49258 | Reflected cross-site scripting vulnerability | |
| CVE-2023-49259 | Bruteforcing authentication cookie for a given user | |
| CVE-2023-49260 | Stored cross-site scripting vulnerability | |
| CVE-2023-49262 | Buffer overflow vulnerability in Cookie authentication field |
No comments yet