S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-28151 Scanner

CVE-2021-28151 scanner - Command Injection vulnerability in Hongdian H8922

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-28151
8.8
CVSS

Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Hongdian H8922 is a device used for remote monitoring and management of network infrastructure. Specifically, it is used to monitor and manage industrial control systems, such as SCADA (Supervisory Control and Data Acquisition) networks. The device connects to both ethernet and serial networks and has a range of features that allow for quick and efficient troubleshooting of any issues that arise.

One of the vulnerabilities detected in the Hongdian H8922 is CVE-2021-28151. This vulnerability allows for OS command injection via shell metacharacters into the ip-address field of the tools.cgi ping command. This vulnerability is accessible to anyone with the username guest and password guest and could potentially allow an attacker to execute malicious code on the device.

Exploiting this vulnerability could lead to a range of consequences for a company or organization. An attacker could easily gain access to sensitive information or take control of key systems, potentially leading to expensive outages or even damage to physical infrastructure. This vulnerability should therefore be taken seriously and addressed as quickly as possible to avoid any potential negative impacts.

Overall, it is important for companies and organizations to be aware of vulnerabilities like CVE-2021-28151 and take proactive steps to protect their digital assets. By using a platform like s4e.io, companies can stay informed about the latest known vulnerabilities and take action quickly to maintain the security of their network infrastructure. Don't hesitate to invest in the protection of your systems and take the necessary steps to keep them secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are a number of precautions that can be taken, including:

  • Changing the default username and password on the device to something more secure.
  • Disabling the tools.cgi feature and any other unnecessary services.
  • Limiting access to the device to only authorized personnel.
  • Keeping the device up-to-date with the latest firmware and security patches.
  • Monitoring the device for any suspicious activity and responding immediately to any potential threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-28151 scanner - Command Injection vulnerability in Hongdian H8922 | S4E