VYPR
High severity8.8NVD Advisory· Published Jun 23, 2022· Updated Jun 17, 2026

CVE-2021-26637

CVE-2021-26637

Description

There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.

Affected products

10
  • SiHAS/ACM-300llm-fuzzy
  • SiHAS/GCM-300llm-fuzzy
  • SiHAS/SGW-300llm-fuzzy
  • cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:android:*:*
    • cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:iphone_os:*:*
  • cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:android:*:*
    • cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:iphone_os:*:*
  • cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:android:*:*
    • cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:iphone_os:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.