CVE-2021-26637

There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
References
Link Resource
https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66782 Broken Link Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:h:shinasys:sihas_sgw-300:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:h:shinasys:sihas_acm-300:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:h:shinasys:sihas_gcm-300:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-06-23 17:15

Updated : 2023-06-26 17:49


NVD link : CVE-2021-26637

Mitre link : CVE-2021-26637

CVE.ORG link : CVE-2021-26637


JSON object : View

Products Affected

shinasys

  • sihas_gcm-300_firmware
  • sihas_sgw-300_firmware
  • sihas_acm-300_firmware
  • sihas_gcm-300
  • sihas_acm-300
  • sihas_sgw-300
CWE
CWE-306

Missing Authentication for Critical Function

CWE-862

Missing Authorization

CWE-287

Improper Authentication