CVE-2021-26637

There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:h:shinasys:sihas_sgw-300:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:h:shinasys:sihas_acm-300:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:h:shinasys:sihas_gcm-300:-:*:*:*:*:*:*:*

Information

Published : 2022-06-23 10:15

Updated : 2022-06-29 09:50


NVD link : CVE-2021-26637

Mitre link : CVE-2021-26637


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

shinasys

  • sihas_gcm-300
  • sihas_acm-300
  • sihas_sgw-300_firmware
  • sihas_gcm-300_firmware
  • sihas_acm-300_firmware
  • sihas_sgw-300