CVE-2021-41506: Critical severity xiongmaitech ahb7008t-mh-v2 vulnerability
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI351850H10LS39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41506?
CVE-2021-41506 is a critical vulnerability affecting several models of Xiaongmai DVRs.
How severe is CVE-2021-41506?
CVE-2021-41506 has a severity score of 9.8, which is classified as critical.
Which software versions are affected by CVE-2021-41506?
The affected software versions are: AHB7008T-MH-V2 firmware 4.02.R11.7601.Nat.Onvif.20170420, AHB7804R-ELS firmware 4.02.R11.Nat.Onvif.20160422, AHB7804R-MH-V2 firmware 4.02.R11.7601.Nat.Onvif.20170424, AHB7808R-MS-V2 firmware 4.02.R11.Nat.Onvif.20170327, AHB7808R-MS firmware 4.02.R11.Nat.Onvif.20161205, and AHB7808T-MS-V2 firmware 4.02.R11.Nat.Onvifc.20161205.
How can I fix CVE-2021-41506?
Currently, there is no official patch available for CVE-2021-41506. It is recommended to contact the vendor for further guidance.
Are there any references related to CVE-2021-41506?
Yes, you can find more information about CVE-2021-41506 at the following links: [link1](https://github.com/Snawoot/hisilicon-dvr-telnet), [link2](https://github.com/tothi/hs-dvr-telnet), [link3](https://habr.com/en/post/486856/).