A vulnerability has been found in E-Lins H685, H685f, H700, H720, H750, H820, H820Q, H820Q0 and H900 up to 3.2 and classified as critical. This vulnerability affects unknown code of the component OEM Backend. The manipulation leads to hard-coded credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. The vendor was contacted early about this disclosure but did not respond in any way.
History

Mon, 25 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
First Time appeared E-lins
E-lins h685
E-lins h685f
E-lins h700
E-lins h720
E-lins h750
E-lins h820
E-lins h820q
E-lins h820q0
E-lins h900
CPEs cpe:2.3:a:e-lins:h685:*:*:*:*:*:*:*:*
cpe:2.3:a:e-lins:h685f:*:*:*:*:*:*:*:*
cpe:2.3:a:e-lins:h700:*:*:*:*:*:*:*:*
cpe:2.3:a:e-lins:h720:*:*:*:*:*:*:*:*
cpe:2.3:a:e-lins:h750:*:*:*:*:*:*:*:*
cpe:2.3:a:e-lins:h820:*:*:*:*:*:*:*:*
cpe:2.3:a:e-lins:h820q0:*:*:*:*:*:*:*:*
cpe:2.3:a:e-lins:h820q:*:*:*:*:*:*:*:*
cpe:2.3:a:e-lins:h900:*:*:*:*:*:*:*:*
Vendors & Products E-lins
E-lins h685
E-lins h685f
E-lins h700
E-lins h720
E-lins h750
E-lins h820
E-lins h820q
E-lins h820q0
E-lins h900
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 22 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in E-Lins H685, H685f, H700, H720, H750, H820, H820Q, H820Q0 and H900 up to 3.2 and classified as critical. This vulnerability affects unknown code of the component OEM Backend. The manipulation leads to hard-coded credentials. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. The vendor was contacted early about this disclosure but did not respond in any way.
Title E-Lins H685/H685f/H700/H720/H750/H820/H820Q/H820Q0/H900 OEM Backend hard-coded credentials
Weaknesses CWE-259
CWE-798
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-11-22T22:00:07.324Z

Updated: 2024-11-25T21:23:06.245Z

Reserved: 2024-11-22T17:00:20.839Z

Link: CVE-2024-11630

cve-icon Vulnrichment

Updated: 2024-11-25T21:21:33.608Z

cve-icon NVD

Status : Received

Published: 2024-11-22T22:15:13.637

Modified: 2024-11-22T22:15:13.637

Link: CVE-2024-11630

cve-icon Redhat

No data.