cbcvebase.
CVE-2020-22253
published 2022-04-06

CVE-2020-22253: Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39…

PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.06%
60.2th percentile
Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitrary Telnet connections with the victim device.

Affected

8 ranges
VendorProductVersion rangeFixed in
xiongmaitechahb7008t-mh-v2_firmware
xiongmaitechahb7804r-els_firmware
xiongmaitechahb7804r-lms_firmware
xiongmaitechahb7804r-mh-v2_firmware
xiongmaitechahb7808r-ms-v2_firmware
xiongmaitechahb7808r-ms_firmware
xiongmaitechahb7808t-ms-v2_firmware
xiongmaitechhi3518e_50h10l_s39_firmware

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.