« Volver al listado

CVE-2021-26611

Estado: ModificadaCrítica (9.8)—

La cámara IP HejHome GKW-IC052 contenía una vulnerabilidad de credenciales embebidas. Este problema permite a atacantes remotos operar la cámara IP (reinicio, restablecimiento de fábrica, instantánea, etc.)

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-26611",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "vuln@krcert.or.kr",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vuln@krcert.or.kr",
      "affectedData": [
        {
          "vendor": "Goqual",
          "product": "GKW-IC052",
          "versions": [
            {
              "status": "affected",
              "version": "2.9.5"
            },
            {
              "status": "affected",
              "version": "2.9.6"
            },
            {
              "status": "affected",
              "version": "2.9.7"
            },
            {
              "status": "affected",
              "version": "4.0.4"
            }
          ],
          "platforms": [
            "N/A"
          ]
        }
      ]
    }
  ],
  "published": "2021-11-26T17:15:07.627",
  "references": [
    {
      "url": "https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36359",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vuln@krcert.or.kr"
    },
    {
      "url": "https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36359",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vuln@krcert.or.kr",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, factory reset, snapshot etc..)"
    },
    {
      "lang": "es",
      "value": "La cámara IP HejHome GKW-IC052 contenía una vulnerabilidad de credenciales embebidas. Este problema permite a atacantes remotos operar la cámara IP (reinicio, restablecimiento de fábrica, instantánea, etc.)"
    }
  ],
  "lastModified": "2026-06-17T03:43:33.697",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hej:hejhome_gkw-ic052_firmware:2.9.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FAB580B-0B6A-4885-BAC8-D70424EFCE79"
            },
            {
              "criteria": "cpe:2.3:o:hej:hejhome_gkw-ic052_firmware:2.9.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D495EE02-92E2-4ADB-A8D4-31B7DF70C326"
            },
            {
              "criteria": "cpe:2.3:o:hej:hejhome_gkw-ic052_firmware:2.9.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A937EE4E-46A8-425A-B1FD-4B4FA042F9FA"
            },
            {
              "criteria": "cpe:2.3:o:hej:hejhome_gkw-ic052_firmware:4.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C75221AF-0F70-4258-9A74-34384D1B3026"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hej:hejhome_gkw-ic052:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B318C7A3-929B-4798-B647-FF2A49CF22DC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vuln@krcert.or.kr"
}