CVE-2017-14335 - CVE House
Back to Database
Status published High CVE-2017-14335

On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not...

Vulnerability Description

On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-14335

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

hb7024xt firmware, hb7032xt firmware, hb7008t2 firmware, hb7016t2 firmware, hb7204xt firmware, hb7208xt firmware, hb7216xt firmware, hb7208x3 firmware, hb7216x3 firmware, hb7204x firmware, hb7208x firmware, hb7216x firmware, 7204xr firmware, 7208xr firmware, 7216xr firmware, hb7004k firmware, hb7004kh firmware, hb7008kc firmware, hb7008kce firmware, hb7008kh firmware, hb7008khe firmware, hb7204kl firmware, hb7204kk firmware, hb7016lc firmware, hb7016lh firmware, hb7116x3 firmware, hb7108x3 firmware, hb8004 firmware, hb8008 firmware, hb8016 firmware, hb8004r firmware, hb8008r firmware, hb8016r firmware, hb8204h firmware, hb8208h firmware, hb8216h firmware, hb8204hr firmware, hb8208hr firmware, hb8216hr firmware, hb8208x3 firmware, hb8216x3 firmware, hb8608x3 firmware, hb8616x3 firmware, hb8808x3 firmware, hb8816x3 firmware, hb9404x3 firmware, hb9408x3 firmware, hb9604x3 firmware, hb9608x3 firmware, hb9012x3 firmware, hb9020x3 firmware, hb9212x3 firmware, hb9220x3 firmware, hb7904 firmware, hb7908 firmware, hb7916s firmware, hb7904x firmware, hb7908x firmware, hb7916sx firmware, hb9904 firmware, hb9908 firmware, hb9912 firmware, hb9916 firmware, hb9924 firmware, hb9932 firmware, hb9808n04 firmware, hb9816n08 firmware, hb9824n16 firmware, hb9832n16 firmware
Vulnerable Versions:
Unknown

Timeline

Official Publish: September 12th, 2017
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.