High severity8.8NVD Advisory· Published Jun 23, 2022· Updated Jun 17, 2026
CVE-2021-26637
CVE-2021-26637
Description
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.
Affected products
10- Range: old app
cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:android:*:*+ 1 more
- cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:android:*:*
- cpe:2.3:o:shinasys:sihas_sgw-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:android:*:*+ 1 more
- cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:android:*:*
- cpe:2.3:o:shinasys:sihas_acm-300_firmware:-:*:*:*:*:iphone_os:*:*
cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:android:*:*+ 1 more
- cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:android:*:*
- cpe:2.3:o:shinasys:sihas_gcm-300_firmware:-:*:*:*:*:iphone_os:*:*
Patches
Vulnerability mechanics
References
1- www.krcert.or.kr/krcert/secNoticeView.donvdBroken LinkThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.