Vulnerability Details CVE-2021-28151
Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with the username guest and password guest.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.927
EPSS Ranking 99.7%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2021-28151
-
cpe:2.3:h:hongdian:h8922:-
-
cpe:2.3:o:hongdian:h8922_firmware:3.0.5