Hongdian Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Hongdian products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
3
In CISA KEV
0
Beyond CISA KEV
3
Sensor Observed
0
Virtual Patch Available
0
Hongdian KEVs Added by Year
3 Hongdian KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2021-28151
Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping... |
H8922 | High | Not in CISA | 04 Oct 2025 |
|
CVE-2021-28149
Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote... |
H8922 | High | Not in CISA | 06 May 2021 |
|
CVE-2021-28150
Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via... |
H8922 | High | Not in CISA | 06 May 2021 |
Common Vulnerability Classes (CWE)
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
- CWE-425 — Direct Request ('Forced Browsing') 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology