.. / CVE-2021-28151

Exploit for Hongdian H8922 3.0.5 - Remote Command Injection (CVE-2021-28151)

Description:

Hongdian H8922 3.0.5 devices are susceptible to remote command injection via shell metacharacters into the ip-address (a/k/a Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system.

Nuclei Template

View the template here CVE-2021-28151.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-28151.yaml
Copy

References:

https://github.com/ArrestX/--POC
https://ssd-disclosure.com/ssd-advisory-hongdian-h8922-multiple-vulnerabilities/
https://nvd.nist.gov/vuln/detail/CVE-2021-28151
http://en.hongdian.com/Products/Details/H8922
https://github.com/ARPSyndicate/kenzer-templates