PT-2024-17145 · E Lins · E-Lins H820+6

Liutong

·

Published

2024-11-22

·

Updated

2024-11-23

·

CVE-2024-11630

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions E-Lins H685 versions up to 3.2 E-Lins H685f versions up to 3.2 E-Lins H700 versions up to 3.2 E-Lins H720 versions up to 3.2 E-Lins H750 versions up to 3.2 E-Lins H820 versions up to 3.2 E-Lins H820Q versions up to 3.2 E-Lins H820Q0 versions up to 3.2 E-Lins H900 versions up to 3.2
Description A critical issue has been found in the OEM Backend component, affecting unknown code and leading to hard-coded credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations For E-Lins H685 version up to 3.2, change the configuration settings. For E-Lins H685f version up to 3.2, change the configuration settings. For E-Lins H700 version up to 3.2, change the configuration settings. For E-Lins H720 version up to 3.2, change the configuration settings. For E-Lins H750 version up to 3.2, change the configuration settings. For E-Lins H820 version up to 3.2, change the configuration settings. For E-Lins H820Q version up to 3.2, change the configuration settings. For E-Lins H820Q0 version up to 3.2, change the configuration settings. For E-Lins H900 version up to 3.2, change the configuration settings.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-11630

Affected Products

E-Lins H685
E-Lins H700
E-Lins H720
E-Lins H750
E-Lins H820
E-Lins H820Q0
E-Lins H900