cbcvebase.
CVE-2016-6825
published 2016-09-07

CVE-2016-6825: Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3…

PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.13%
79.9th percentile
Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, and RH2288H V3 servers with software before V100R003C00SPC515 allow remote attackers to obtain passwords via a brute-force attack, related to "lack of authentication protection mechanisms."

Affected

6 ranges
VendorProductVersion rangeFixed in
huaweirh1288_v3_server_firmware
huaweirh2288_v3_server_firmware
huaweirh2288h_v3_server_firmware
huaweixh620_v3_server_firmware
huaweixh622_v3_server_firmware
huaweixh628_v3_server_firmware

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.