.. / CVE-2021-28150

Exploit for Hongdian H8922 3.0.5 - Information Disclosure (CVE-2021-28150)

Description:

Hongdian H8922 3.0.5 is susceptible to information disclosure. An attacker can access cli.conf (with the administrator password and other sensitive data) via /backup2.cgi and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Nuclei Template

View the template here CVE-2021-28150.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-28150.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2021-28150
https://ssd-disclosure.com/ssd-advisory-hongdian-h8922-multiple-vulnerabilities/
https://github.com/Threekiii/Awesome-POC
http://en.hongdian.com/Products/Details/H8922
https://github.com/SexyBeast233/SecBooks