Some Huawei home routers have an improper authorization vulnerability
Published Nov 29, 2019
7.8
HIGHCVSS 3.1
EPSS 0.22%
Description
Some Huawei home routers have an improper authorization vulnerability. Due to improper authorization of certain programs, an attacker can exploit this vulnerability to execute uploaded malicious files and escalate privilege.
Affected products
No data.
Configuration 1
- ≥ 10.0.2.2 · < 10.0.2.7
Configuration 2
- ≥ 10.0.2.3 · < 10.0.2.5
Configuration 3
- ≥ 9.0.3.3 · < 10.0.2.5
Configuration 4
- ≥ 9.0.2.23 · < 10.0.2.5
Configuration 5
- ≥ 9.0.2.3 · < 10.0.2.5
Running on/with
- n/a
Configuration 6
- ≥ 9.0.3.9 · < 10.0.2.6
Running on/with
- n/a
Configuration 7
- ≥ 9.0.3.9 · < 10.0.2.5
Running on/with
- n/a
Configuration 8
- ≥ 10.0.2.8 · < 10.0.2.9
Running on/with
- n/a
Configuration 9
- ≥ 10.0.2.8 · < 10.0.2.9
Running on/with
- n/a
Configuration 10
- ≥ 9.0.3.11 · < 10.0.2.5
Running on/with
- n/a
Configuration 11
- ≥ 10.0.2.3 · < 10.0.2.5
Configuration 12
- ≥ 9.0.3.11 · < 10.0.2.7
Configuration 13
- ≥ 10.0.2.2 · < 10.0.2.7
Configuration 14
- ≥ 10.0.2.2 · < 10.0.2.7
Configuration 15
- ≥ 10.0.2.2 · < 10.0.2.7
Configuration 16
- ≥ 9.0.3.9 · < 10.0.2.6
Configuration 17
- 9.0.3.11
- 10.0.2.3
Configuration 18
- ≥ 9.0.3.22 · < 10.0.2.6
Configuration 19
- ≥ 9.0.3.22 · < 10.0.2.6
Configuration 20
- ≥ 10.0.2.3 · < 10.0.2.5
Configuration 21
- ≥ 10.0.2.2 · < 10.0.2.7
Configuration 22
- ≥ 9.0.3.11 · < 10.0.2.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (1)
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191113-01-homerouter-en x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191113-01-homerouter-en | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.