logo

Vulnerabilities in Hongdian Router H8951-4G-ESP software

ID: 1b16319a-f933-5ed8-8f58-4136cf272a75

STIX ID: report--1b16319a-f933-5ed8-8f58-4136cf272a75

Feed Name: CERT Polska

Threat Score
75/100

Date Published: 2024-01-12

Date Updated: 2026-04-19

Author: CERT Polska

...
...

CERT Polska coordinated disclosure identifies ten vulnerabilities in the Hongdian H8951-4G-ESP firmware (pre-build 2310271149) that collectively allow privilege escalation to root, remote command execution, unauthenticated console access, decryption of configuration backups via a hardcoded key, arbitrary CGI upload and execution, multiple XSS vectors, predictable/weak authentication cookies, and an authentication bypass via cookie overflow; the issues were reported by SEQRED and mitigated in build 2310271149.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.