There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
References
Link | Resource |
---|---|
https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66782 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Information
Published : 2022-06-23 10:15
Updated : 2022-06-29 09:50
NVD link : CVE-2021-26637
Mitre link : CVE-2021-26637
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
shinasys
- sihas_gcm-300
- sihas_acm-300
- sihas_sgw-300_firmware
- sihas_gcm-300_firmware
- sihas_acm-300_firmware
- sihas_sgw-300