VCM5010 with software versions earlier before V100R002C50SPC100 has a command injection vulnerability. This is due to insufficient validation of user's input. An authenticated attacker could launch a command injection attack.
2017-11-22T19:29:01.960
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | huawei | vcm5010_firmware | < v100r002c50spc100 | Yes |
| Hardware | huawei | vcm5010 | - | No |