S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-28149 Scanner

CVE-2021-28149 scanner - Directory Traversal vulnerability in Hongdian H8922

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-28149
6.5
CVSS

Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges to download any file from the device by substituting ../ (e.g., ../../etc/passwd) This can be carried out with a web browser by changing the file name accordingly. Upon visiting log_download.cgi?type=../../etc/passwd and logging in, the web server will allow a download of the contents of the /etc/passwd file.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Hongdian H8922 3.0.5 device is commonly used for remote monitoring of various industrial applications such as environmental monitoring, industrial automation, and power grid management. It is designed to provide real-time data analysis, control, and management capabilities for these applications. The device can remotely connect to various industrial equipment and provide continuous monitoring of their performance.

Recently, a vulnerability named CVE-2021-28149 was detected in the Hongdian H8922 3.0.5 device. This vulnerability allows a remote attacker to perform Directory Traversal attacks. The /log_download.cgi log export handler of the device fails to validate user input, which enables an attacker with minimal privileges to download any file from the device by substituting "../" in the filename. By exploiting this vulnerability, an attacker can easily gain unauthorized access to sensitive information stored on the device.

When this vulnerability is successfully exploited, an attacker can obtain sensitive information such as user credentials, configuration files, and critical system files. They can also access confidential business information stored on the device, compromising the integrity and availability of the overall infrastructure. If exploited, this vulnerability can lead to significant financial losses, impacting the operational capability and reputation of the affected organization.

In conclusion, the Hongdian H8922 3.0.5 device has gained widespread adoption in various industrial applications, but with the recent discovery of the CVE-2021-28149 vulnerability, caution is now essential. With the advanced features of the s4e.io platform, individuals and organizations can quickly and effortlessly identify potential vulnerabilities and take the necessary steps to safeguard their digital assets. Stay safe, stay secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is essential to take precautionary measures such as updating firmware, implementing security controls, and conducting regular vulnerability scans. Here are a few actionable steps that organizations can take to mitigate this vulnerability:

  • Update to the latest firmware version as soon as possible
  • Configure Firewalls to restrict unauthorized access
  • Implement access controls to prevent unauthorized access to sensitive files
  • Regularly conduct vulnerability/penetration tests to identify and remediate other potential vulnerabilities
  • Block the vulnerable URL, /log_download.cgi, from being accessed by unauthenticated users

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-28149 scanner - Directory Traversal vulnerability in Hongdian H8922 | S4E