CVE-2021-41506: Critical severity xiongmaitech ahb7008t-mh-v2 vulnerability

Published Jun 30, 2022
·
Updated

Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI351850H10LS39 V4.02.R11.7601.Nat.Onvif.20170420, V4.02.R11.Nat.Onvif.20160422, V4.02.R11.7601.Nat.Onvif.20170424, V4.02.R11.Nat.Onvif.20170327, V4.02.R11.Nat.Onvif.20161205, V4.02.R11.Nat.20170301, V4.02.R12.Nat.OnvifS.20170727 is affected by a backdoor in the macGuarder and dvrHelper binaries of DVR/NVR/IP camera firmware due to static root account credentials in the system.

Affected Software

16 affected components
Xiongmaitech Ahb7008t-mh-v2 Firmware=4.02.r11.7601.nat.onvif.20170420
Xiongmaitech Ahb7008t-mh-v2
Xiongmaitech Ahb7804r-els Firmware=4.02.r11.nat.onvif.20160422
Xiongmaitech Ahb7804r-els
Xiongmaitech Ahb7804r-mh-v2 Firmware=4.02.r11.7601.nat.onvif.20170424
Xiongmaitech Ahb7804r-mh-v2
Xiongmaitech Ahb7808r-ms-v2 Firmware=4.02.r11.nat.onvif.20170327
Xiongmaitech Ahb7808r-ms-v2
Xiongmaitech Ahb7808r-ms Firmware=4.02.r11.nat.onvif.20160328
Xiongmaitech Ahb7808r-ms
Xiongmaitech Ahb7808t-ms-v2 Firmware=4.02.r11.nat.onvifc.20161205
Xiongmaitech Ahb7808t-ms-v2
Xiongmaitech Ahb7804r-lms Firmware=4.02.r11.nat.20170301
Xiongmaitech Ahb7804r-lms
Xiongmaitech Hi3518e 50h10l S39 Firmware=4.02.r12.nat.onvifs.20170727
Xiongmaitech Hi3518e 50h10l S39

Event History

Jun 30, 2022
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
Description

Frequently Asked Questions

1

What is CVE-2021-41506?

CVE-2021-41506 is a critical vulnerability affecting several models of Xiaongmai DVRs.

2

How severe is CVE-2021-41506?

CVE-2021-41506 has a severity score of 9.8, which is classified as critical.

3

Which software versions are affected by CVE-2021-41506?

The affected software versions are: AHB7008T-MH-V2 firmware 4.02.R11.7601.Nat.Onvif.20170420, AHB7804R-ELS firmware 4.02.R11.Nat.Onvif.20160422, AHB7804R-MH-V2 firmware 4.02.R11.7601.Nat.Onvif.20170424, AHB7808R-MS-V2 firmware 4.02.R11.Nat.Onvif.20170327, AHB7808R-MS firmware 4.02.R11.Nat.Onvif.20161205, and AHB7808T-MS-V2 firmware 4.02.R11.Nat.Onvifc.20161205.

4

How can I fix CVE-2021-41506?

Currently, there is no official patch available for CVE-2021-41506. It is recommended to contact the vendor for further guidance.

5

Are there any references related to CVE-2021-41506?

Yes, you can find more information about CVE-2021-41506 at the following links: [link1](https://github.com/Snawoot/hisilicon-dvr-telnet), [link2](https://github.com/tothi/hs-dvr-telnet), [link3](https://habr.com/en/post/486856/).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203