PT-2024-17145 · E Lins · E-Lins H820+6
Liutong
·
Published
2024-11-22
·
Updated
2024-11-23
·
CVE-2024-11630
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
E-Lins H685 versions up to 3.2
E-Lins H685f versions up to 3.2
E-Lins H700 versions up to 3.2
E-Lins H720 versions up to 3.2
E-Lins H750 versions up to 3.2
E-Lins H820 versions up to 3.2
E-Lins H820Q versions up to 3.2
E-Lins H820Q0 versions up to 3.2
E-Lins H900 versions up to 3.2
Description
A critical issue has been found in the OEM Backend component, affecting unknown code and leading to hard-coded credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations
For E-Lins H685 version up to 3.2, change the configuration settings.
For E-Lins H685f version up to 3.2, change the configuration settings.
For E-Lins H700 version up to 3.2, change the configuration settings.
For E-Lins H720 version up to 3.2, change the configuration settings.
For E-Lins H750 version up to 3.2, change the configuration settings.
For E-Lins H820 version up to 3.2, change the configuration settings.
For E-Lins H820Q version up to 3.2, change the configuration settings.
For E-Lins H820Q0 version up to 3.2, change the configuration settings.
For E-Lins H900 version up to 3.2, change the configuration settings.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
E-Lins H685
E-Lins H700
E-Lins H720
E-Lins H750
E-Lins H820
E-Lins H820Q0
E-Lins H900