CVE-2021-26608
An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware ActiveX module. This issue is due to missing support for integrity check of download URL or downloaded file hash.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.23%
- CWE
- CWE-353
- Published
- 2021-09-09
- Last modified
- 2026-03-13
Affected products
- handysoft HShell.dll
- handysoft HShell.dll
- handysoft HShell.dll
Weakness type
Related vulnerabilities
- CVE-2020-7810 — HandySoft ActiveX File Download and Execution Vulnerability
- CVE-2020-10266 — RVD#1487: No integrity checks on UR+ platform artifacts when installed in the robot
- CVE-2020-7808 — RAONWIZ Inc K Upload, arguments modiffication via missing support for integrity check vulnerability
- CVE-2019-11480 — Ubuntu kernel snap build process could use unauthenticated sources
- CVE-2021-28545 — Acrobat Reader DC Missing Support for Integrity Check
- CVE-2019-12804 — Hunesion i-oneNet Missing Support for Integrity Check vulnerability
- CVE-2023-32475 — Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system c
- CVE-2025-48500 — BIG-IP APM VPN web client for macOS vulnerability