Vulnerabilities > Hbgk

DATE CVE VULNERABILITY TITLE RISK
2017-09-12 CVE-2017-14335 Improper Input Validation vulnerability in Hbgk products
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
network
low complexity
hbgk CWE-20
7.5