Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2026-28806
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper authorization in device bulk actions and device update API allows cross-organization device control
Source: NVD (National Vulnerability Database)
Vulnerability Description
Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bulk actions and device update API. Missing authorization checks in the device bulk actions and device update API endpoints allow authenticated users to target devices belonging to other organizations and perform actions outside of their privilege level. An attacker can select devices outside of their organization by manipulating device identifiers and perform management actions on them, such as moving them to products they control. This may allow attackers to interfere with firmware updates, access device functionality exposed by the platform, or disrupt device connectivity. In environments where additional features such as remote console access are enabled, this could lead to full compromise of affected devices. This issue affects nerves_hub_web: from 1.0.0 before 2.4.0.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
NervesHub 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NervesHub是NervesHub开源的一个管理Nerves设备的固件更新的软件。 NervesHub 1.0.0版本至2.4.0之前版本存在安全漏洞,该漏洞源于设备批量操作和设备更新API缺少授权检查,可能导致跨组织设备控制。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
nerves-hubnerves_hub_web 1.0.0 ~ 2.4.0 cpe:2.3:a:nerves-hub:nerves_hub_web:*:*:*:*:*:*:*:*
nerves-hubnerves_hub_web 1.0.0 ~ 2.4.0 cpe:2.3:a:nerves-hub:nerves_hub_web:*:*:*:*:*:*:*:*
nerves-hubnerves_hub_web adaeefdb7a835525482588f43332ef988cc448c7 ~ 1f69c9d595684a4650c3ac702f3dc7c5bcd7526c cpe:2.3:a:nerves-hub:nerves_hub_web:*:*:*:*:*:*:*:*
II. Public POCs for CVE-2026-28806
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2026-28806
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2026-28806

No comments yet


Leave a comment