CVE-2021-26637

There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
References
Link Resource
https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66782 Broken Link Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:h:shinasys:sihas_sgw-300:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:h:shinasys:sihas_acm-300:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:h:shinasys:sihas_gcm-300:-:*:*:*:*:*:*:*

History

26 Jun 2023, 17:49

Type Values Removed Values Added
CWE CWE-287 CWE-306
CWE-862
References (MISC) https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66782 - Third Party Advisory, VDB Entry (MISC) https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66782 - Broken Link, Third Party Advisory, VDB Entry

29 Jun 2022, 16:50

Type Values Removed Values Added
CPE cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:h:shinasys:sihas_acm-300:-:*:*:*:*:*:*:*
cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:h:shinasys:sihas_sgw-300:-:*:*:*:*:*:*:*
cpe:2.3:h:shinasys:sihas_gcm-300:-:*:*:*:*:*:*:*
cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:iphone_os:*:*
CWE CWE-287
First Time Shinasys
Shinasys sihas Sgw-300 Firmware
Shinasys sihas Sgw-300
Shinasys sihas Acm-300
Shinasys sihas Gcm-300
Shinasys sihas Gcm-300 Firmware
Shinasys sihas Acm-300 Firmware
References (MISC) https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66782 - (MISC) https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66782 - Third Party Advisory, VDB Entry
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8

23 Jun 2022, 17:19

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-23 17:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-26637

Mitre link : CVE-2021-26637

CVE.ORG link : CVE-2021-26637


JSON object : View

Products Affected

shinasys

  • sihas_acm-300_firmware
  • sihas_sgw-300_firmware
  • sihas_gcm-300
  • sihas_gcm-300_firmware
  • sihas_sgw-300
  • sihas_acm-300
CWE
CWE-306

Missing Authentication for Critical Function

CWE-862

Missing Authorization

CWE-287

Improper Authentication