PT-2024-31203 · Shenzhen Haichangxing Technology Co. · Hcx H822 4G Lte Router

Published

2024-09-10

·

Updated

2024-10-29

·

CVE-2024-44667

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router version M7628NNxISPxUIv2 v1.0.1557.15.35 P0
Description The issue is related to Incorrect Access Control, allowing unauthenticated factory mode reset and command injection. This leads to information exposure and root shell access.
Recommendations For version M7628NNxISPxUIv2 v1.0.1557.15.35 P0, as a temporary workaround, consider restricting access to the router's factory mode reset and command injection functionalities until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-44667

Affected Products

Hcx H822 4G Lte Router