Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-7933


Huawei home gateway products HiRouter-CD20 and WS5200 with the versions before HiRouter-CD20-10 1.9.6 and the versions before WS5200-10 1.9.6 have a path traversal vulnerability. Due to the lack of validation while these home gateway products install APK plugins, an attacker tricks a user into installing a malicious APK plugin, and plugin can overwrite arbitrary file of devices. Successful exploit may result in arbitrary code execution or privilege escalation.


Published

2018-05-10T14:29:00.627

Last Modified

2024-11-21T04:12:58.907

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei hirouter-cd20_firmware < hirouter-cd20-10_1.9.6 Yes
Hardware huawei hirouter-cd20 - No
Operating System huawei ws5200_firmware < ws5200-10_1.9.6 Yes
Hardware huawei ws5200 - No

References