Humaxdigital develops a narrowly focused line of consumer set-top box and receiver products, primarily the HG100R and HGB10R series, whose firmware implementations exhibit persistent security weaknesses centered on cleartext transmission, credential exposure, cross-site scripting, and missing authentication controls. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code, reflecting the accessible nature of consumer devices and the severity of authentication and data-confidentiality flaws in entertainment and set-top box firmware. Defenders should treat firmware updates for these devices as high-priority; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Humaxdigital over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11435CRITICAL The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remo | Jul 19, 2017 | 9.8 | 45 | NO | YES |
CVE-2017-7317CRITICAL An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup file, aka GatewaySettings.bin. | Jul 4, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-7315CRITICAL An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router credentials are stored in plaintext | Jul 4, 2017 | 9.8 | 30 | NO | NO |
CVE-2020-9477CRITICAL An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in the web-based interface could allow an unauthenticated remo | Mar 4, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-9370CRITICAL HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking. | Mar 5, 2020 | 9.1 | 28 | NO | NO |
CVE-2019-19889HIGH An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin credentials in the backup file, aka backupsettings.conf. | Dec 18, 2019 | 7.5 | 23 | NO | NO |
CVE-2019-19890HIGH An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP. | Dec 18, 2019 | 7.5 | 22 | NO | NO |
CVE-2017-7316MEDIUM An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is XSS on the 404 page. | Jul 4, 2017 | 6.1 | 20 | NO | NO |
CVE-2020-27366MEDIUM Cross Site Scripting (XSS) vulnerability in wlscanresults.html in Humax HGB10R-02 BRGCAB version 1.0.03, allows local attackers to execute arbitrary code. | Aug 28, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Humaxdigital.
Media articles that mention a CVE ID that affects a product developed by Humaxdigital — matched by CVE ID, not by vendor name.