CVE-2017-14335

On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
hbgkhb7024xt_firmware
-
hbgkhb7032xt_firmware
-
hbgkhb7008t2_firmware
-
hbgkhb7016t2_firmware
-
hbgkhb7204xt_firmware
-
hbgkhb7208xt_firmware
-
hbgkhb7216xt_firmware
-
hbgkhb7208x3_firmware
-
hbgkhb7216x3_firmware
-
hbgkhb7204x_firmware
-
hbgkhb7208x_firmware
-
hbgkhb7216x_firmware
-
hbgk7204xr_firmware
-
hbgk7208xr_firmware
-
hbgk7216xr_firmware
-
hbgkhb7004k_firmware
-
hbgkhb7004kh_firmware
-
hbgkhb7008kc_firmware
-
hbgkhb7008kce_firmware
-
hbgkhb7008kh_firmware
-
hbgkhb7008khe_firmware
-
hbgkhb7204kl_firmware
-
hbgkhb7204kk_firmware
-
hbgkhb7016lc_firmware
-
hbgkhb7016lh_firmware
-
hbgkhb7116x3_firmware
-
hbgkhb7108x3_firmware
-
hbgkhb8004_firmware
-
hbgkhb8008_firmware
-
hbgkhb8016_firmware
-
hbgkhb8004r_firmware
-
hbgkhb8008r_firmware
-
hbgkhb8016r_firmware
-
hbgkhb8204h_firmware
-
hbgkhb8208h_firmware
-
hbgkhb8216h_firmware
-
hbgkhb8204hr_firmware
-
hbgkhb8208hr_firmware
-
hbgkhb8216hr_firmware
-
hbgkhb8208x3_firmware
-
hbgkhb8216x3_firmware
-
hbgkhb8608x3_firmware
-
hbgkhb8616x3_firmware
-
hbgkhb8808x3_firmware
-
hbgkhb8816x3_firmware
-
hbgkhb9404x3_firmware
-
hbgkhb9408x3_firmware
-
hbgkhb9604x3_firmware
-
hbgkhb9608x3_firmware
-
hbgkhb9012x3_firmware
-
hbgkhb9020x3_firmware
-
hbgkhb9212x3_firmware
-
hbgkhb9220x3_firmware
-
hbgkhb7904_firmware
-
hbgkhb7908_firmware
-
hbgkhb7916s_firmware
-
hbgkhb7904x_firmware
-
hbgkhb7908x_firmware
-
hbgkhb7916sx_firmware
-
hbgkhb9904_firmware
-
hbgkhb9908_firmware
-
hbgkhb9912_firmware
-
hbgkhb9916_firmware
-
hbgkhb9924_firmware
-
hbgkhb9932_firmware
-
hbgkhb9808n04_firmware
-
hbgkhb9816n08_firmware
-
hbgkhb9824n16_firmware
-
hbgkhb9832n16_firmware
-
𝑥
= Vulnerable software versions