CVE-2020-22253 describes a critical vulnerability affecting several Xiongmai Technology Co devices, including various AHB7008T, AHB7804R, AHB7808R, and HI3518E models. The vulnerability stems from an open port 9530, which allows unauthenticated attackers to establish arbitrary Telnet connections to the affected devices. With a CVSS score of 9.8 (Critical), this flaw presents a severe risk due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or significant community discussion, the high FAUCET Risk Score of 79/100 indicates a substantial inherent risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.02.r11.7601.nat.onvifc.20170420CPE matchmatch criteria | cpe:2.3:o:xiongmaitech:ahb7008t-mh-v2_firmware:4.02.r11.7601.nat.onvifc.20170420:*:*:*:*:*:*:* | ||
4.02.r11.nat.onvifc.20160422CPE matchmatch criteria | cpe:2.3:o:xiongmaitech:ahb7804r-els_firmware:4.02.r11.nat.onvifc.20160422:*:*:*:*:*:*:* | ||
4.02.r11.7601.nat.onvifc.20170424CPE matchmatch criteria | cpe:2.3:o:xiongmaitech:ahb7804r-mh-v2_firmware:4.02.r11.7601.nat.onvifc.20170424:*:*:*:*:*:*:* | ||
4.02.r11.nat.onvifc.20170327CPE matchmatch criteria | cpe:2.3:o:xiongmaitech:ahb7808r-ms-v2_firmware:4.02.r11.nat.onvifc.20170327:*:*:*:*:*:*:* | ||
4.02.r11.nat.onvifc.20170328CPE matchmatch criteria | cpe:2.3:o:xiongmaitech:ahb7808r-ms_firmware:4.02.r11.nat.onvifc.20170328:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.