Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hongdian

First CVE: May 6, 2021Active for: 5 yearsTotal CVEs: 14
58.4
VTI Score
TOP TARGET

Hongdian manufactures industrial and embedded networking devices, notably its H8951 4G cellular gateway product line, which sit in critical infrastructure and remote-monitoring deployments where direct internet exposure is common. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code, driven by recurring authentication bypass, hard-coded credential, OS command injection, and cross-site scripting weaknesses that are typical of embedded systems with limited input validation and access controls. Defenders should treat Hongdian device firmware updates as urgent where devices are internet-accessible; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hongdian over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 6, 2021
5 years ago
Most Recent CVE
Jan 12, 2024
925 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-28151HIGH
Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with
May 6, 20218.851NOYES
CVE-2021-28149MEDIUM
Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges t
May 6, 20216.539NOYES
CVE-2021-28152CRITICAL
Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the telnet service is used on port 5188 with the default credent
May 6, 20219.830NONO
CVE-2021-28150MEDIUM
Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via /backup2.cgi.
May 6, 20215.530NOYES
CVE-2023-49253CRITICAL
Root user password is hardcoded into the device and cannot be changed in the user interface.
Jan 12, 20249.829NONO
CVE-2023-49255CRITICAL
The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. I
Jan 12, 20249.827NONO
CVE-2023-49262CRITICAL
The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.
Jan 12, 20249.826NONO
CVE-2023-49257HIGH
An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privileges.
Jan 12, 20248.824NONO
CVE-2023-49254HIGH
Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test tools. This is similar to the
Jan 12, 20248.822NONO
CVE-2023-49261HIGH
The "tokenKey" value used in user authorization is visible in the HTML source of the login page.
Jan 12, 20247.521NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
29%
43%
29%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (7.1%)
Network13 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (85.7%)
Unknown0 (0.0%)
Required2 (14.3%)
Privileges Required
Low5 (35.7%)
High0 (0.0%)
None9 (64.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
21.4% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hongdian.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hongdian — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hongdian's Products

View all 2 CNAs →

Top CWEs