Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Due to insufficient verification of the input, this could be exploited to obtain the management privilege of the system.
2018-05-24T14:29:00.530
2024-11-21T04:12:56.947
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | huawei | 1288h_v5_firmware | v100r005c00 | Yes |
Hardware | huawei | 1288h_v5 | - | No |
Operating System | huawei | 2288h_v5_firmware | v100r005c00 | Yes |
Hardware | huawei | 2288h_v5 | - | No |