Lucene search

K
cveHuaweiCVE-2018-7933
HistoryMay 10, 2018 - 2:29 p.m.

CVE-2018-7933

2018-05-1014:29:00
CWE-22
huawei
web.nvd.nist.gov
29
huawei
home gateway
hirouter-cd20
ws5200
vulnerability
path traversal
validation
apk plugins
exploit
code execution
privilege escalation
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

31.0%

Huawei home gateway products HiRouter-CD20 and WS5200 with the versions before HiRouter-CD20-10 1.9.6 and the versions before WS5200-10 1.9.6 have a path traversal vulnerability. Due to the lack of validation while these home gateway products install APK plugins, an attacker tricks a user into installing a malicious APK plugin, and plugin can overwrite arbitrary file of devices. Successful exploit may result in arbitrary code execution or privilege escalation.

Affected configurations

Nvd
Vulners
Node
huaweihirouter-cd20_firmwareRange<hirouter-cd20-10_1.9.6
AND
huaweihirouter-cd20Match-
Node
huaweiws5200_firmwareRange<ws5200-10_1.9.6
AND
huaweiws5200Match-
VendorProductVersionCPE
huaweihirouter-cd20_firmware*cpe:2.3:o:huawei:hirouter-cd20_firmware:*:*:*:*:*:*:*:*
huaweihirouter-cd20-cpe:2.3:h:huawei:hirouter-cd20:-:*:*:*:*:*:*:*
huaweiws5200_firmware*cpe:2.3:o:huawei:ws5200_firmware:*:*:*:*:*:*:*:*
huaweiws5200-cpe:2.3:h:huawei:ws5200:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "HiRouter-CD20, WS5200",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "HiRouter-CD20 The versions before HiRouter-CD20-10 1.9.6, WS5200 The versions before WS5200-10 1.9.6"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

31.0%

Related for CVE-2018-7933