Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-7907


Some Huawei products Agassi-L09 AGS-L09C100B257CUSTC100D001, AGS-L09C170B253CUSTC170D001, AGS-L09C199B251CUSTC199D001, AGS-L09C229B003CUSTC229D001, Agassi-W09 AGS-W09C100B257CUSTC100D001, AGS-W09C128B252CUSTC128D001, AGS-W09C170B252CUSTC170D001, AGS-W09C229B251CUSTC229D001, AGS-W09C331B003CUSTC331D001, AGS-W09C794B001CUSTC794D001, Baggio2-U01A BG2-U01C100B160CUSTC100D001, BG2-U01C170B160CUSTC170D001, BG2-U01C199B162CUSTC199D001, BG2-U01C209B160CUSTC209D001, BG2-U01C333B160CUSTC333D001, Bond-AL00C Bond-AL00CC00B201, Bond-AL10B Bond-AL10BC00B201, Bond-TL10B Bond-TL10BC01B201, Bond-TL10C Bond-TL10CC01B131, Haydn-L1JB HDN-L1JC137B068, Kobe-L09A KOB-L09C100B252CUSTC100D001, KOB-L09C209B002CUSTC209D001, KOB-L09C362B001CUSTC362D001, Kobe-L09AHN KOB-L09C233B226, Kobe-W09C KOB-W09C128B251CUSTC128D001, LelandP-L22C 8.0.0.101(C675CUSTC675D2), LelandP-L22D 8.0.0.101(C675CUSTC675D2), Rhone-AL00 Rhone-AL00C00B186, Selina-L02 Selina-L02C432B153, Stanford-L09S Stanford-L09SC432B183, Toronto-AL00 Toronto-AL00C00B223, Toronto-AL00A Toronto-AL00AC00B223, Toronto-TL10 Toronto-TL10C01B223 have a sensitive information leak vulnerability. An attacker can trick a user to install a malicious application to exploit this vulnerability. Due to insufficient verification of the input, successful exploitation can cause sensitive information leak.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 5.5, requiring local system access to exploit with relatively low complexity though user interaction is required and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), for affected systems. Impacting 38 products from huawei, from huawei, from huawei and 35 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2018, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2018-09-26T13:29:00.527

Last Modified

2024-11-21T04:12:57.170

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei agassi-l09_firmware ags-l09c100b257custc100d001 Yes
Operating System huawei agassi-l09_firmware ags-l09c170b253custc170d001 Yes
Operating System huawei agassi-l09_firmware ags-l09c199b251custc199d001 Yes
Operating System huawei agassi-l09_firmware ags-l09c229b003custc229d001 Yes
Hardware huawei agassi-l09 - No
Operating System huawei agassi-w09_firmware ags-w09c100b257custc100d001 Yes
Operating System huawei agassi-w09_firmware ags-w09c128b252custc128d001 Yes
Operating System huawei agassi-w09_firmware ags-w09c170b252custc170d001 Yes
Operating System huawei agassi-w09_firmware ags-w09c229b251custc229d001 Yes
Operating System huawei agassi-w09_firmware ags-w09c331b003custc331d001 Yes
Operating System huawei agassi-w09_firmware ags-w09c794b001custc794d001 Yes
Hardware huawei agassi-w09 - No
Operating System huawei baggio2-u01a_firmware bg2-u01c100b160custc100d001 Yes
Operating System huawei baggio2-u01a_firmware bg2-u01c170b160custc170d001 Yes
Operating System huawei baggio2-u01a_firmware bg2-u01c199b162custc199d001 Yes
Operating System huawei baggio2-u01a_firmware bg2-u01c209b160custc209d001 Yes
Operating System huawei baggio2-u01a_firmware bg2-u01c333b160custc333d001 Yes
Hardware huawei baggio2-u01a - No
Operating System huawei bond-al00c_firmware bond-al00cc00b201 Yes
Hardware huawei bond-al00c - No
Operating System huawei bond-al10b_firmware bond-al10bc00b201 Yes
Hardware huawei bond-al10b - No
Operating System huawei bond-tl10b_firmware bond-tl10bc01b201 Yes
Hardware huawei bond-tl10b - No
Operating System huawei bond-tl10c_firmware bond-tl10cc01b131 Yes
Hardware huawei bond-tl10c - No
Operating System huawei haydn-l1jb_firmware hdn-l1jc137b068 Yes
Hardware huawei haydn-l1jb - No
Operating System huawei kobe-l09a_firmware kob-l09c100b252custc100d001 Yes
Operating System huawei kobe-l09a_firmware kob-l09c209b002custc209d001 Yes
Operating System huawei kobe-l09a_firmware kob-l09c362b001custc362d001 Yes
Hardware huawei kobe-l09a - No
Operating System huawei kobe-l09ahn_firmware kob-l09c233b226 Yes
Hardware huawei kobe-l09ahn - No
Operating System huawei kobe-w09c_firmware kob-w09c128b251custc128d001 Yes
Hardware huawei kobe-w09c - No
Operating System huawei lelandp-l22c_firmware 8.0.0.101_c675custc675d2 Yes
Hardware huawei lelandp-l22c - No
Operating System huawei lelandp-l22d_firmware 8.0.0.101_c675custc675d2 Yes
Hardware huawei lelandp-l22d - No
Operating System huawei rhone-al00_firmware rhone-al00c00b186 Yes
Hardware huawei rhone-al00 - No
Operating System huawei selina-l02_firmware selina-l02c432b153 Yes
Hardware huawei selina-l02 - No
Operating System huawei stanford-l09s_firmware stanford-l09sc432b183 Yes
Hardware huawei stanford-l09s - No
Operating System huawei toronto-al00_firmware toronto-al00c00b223 Yes
Hardware huawei toronto-al00 - No
Operating System huawei toronto-al00a_firmware toronto-al00ac00b223 Yes
Hardware huawei toronto-al00a - No
Operating System huawei toronto-tl10_firmware toronto-tl10c01b223 Yes
Hardware huawei toronto-tl10 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For huawei's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.