Hongdian Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Hongdian products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

3

In CISA KEV

0

Beyond CISA KEV

3

Sensor Observed

0

Virtual Patch Available

0

Hongdian KEVs Added by Year

Loading...

3 Hongdian KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2021-28151

Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping...

High Not in CISA 04 Oct 2025
CVE-2021-28149

Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote...

High Not in CISA 06 May 2021
CVE-2021-28150

Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via...

High Not in CISA 06 May 2021

Common Vulnerability Classes (CWE)

  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
  • CWE-425 — Direct Request ('Forced Browsing') 1
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology