Hongdian manufactures industrial and embedded networking devices, notably its H8951 4G cellular gateway product line, which sit in critical infrastructure and remote-monitoring deployments where direct internet exposure is common. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code, driven by recurring authentication bypass, hard-coded credential, OS command injection, and cross-site scripting weaknesses that are typical of embedded systems with limited input validation and access controls. Defenders should treat Hongdian device firmware updates as urgent where devices are internet-accessible; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hongdian over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28151HIGH Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) field to the tools.cgi ping command, which is accessible with | May 6, 2021 | 8.8 | 51 | NO | YES |
CVE-2021-28149MEDIUM Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges t | May 6, 2021 | 6.5 | 39 | NO | YES |
CVE-2021-28152CRITICAL Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the telnet service is used on port 5188 with the default credent | May 6, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-28150MEDIUM Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and other sensitive data) via /backup2.cgi. | May 6, 2021 | 5.5 | 30 | NO | YES |
CVE-2023-49253CRITICAL Root user password is hardcoded into the device and cannot be changed in the user interface.
| Jan 12, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-49255CRITICAL The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, the session state is shared. I | Jan 12, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-49262CRITICAL The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session. | Jan 12, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-49257HIGH An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privileges. | Jan 12, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-49254HIGH Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test tools. This is similar to the | Jan 12, 2024 | 8.8 | 22 | NO | NO |
CVE-2023-49261HIGH The "tokenKey" value used in user authorization is visible in the HTML source of the login page. | Jan 12, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hongdian.
Media articles that mention a CVE ID that affects a product developed by Hongdian — matched by CVE ID, not by vendor name.