cbcvebase.
CVE-2016-6901
published 2016-09-26

CVE-2016-6901: Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR3600 routers with software before…

PriorityP428medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
0.99%
58.3th percentile
Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR3600 routers with software before V200R007C00SPC900 and NetEngine 16EX routers with software before V200R007C00SPC900 allows remote authenticated users to cause a denial of service via format string specifiers in vectors involving partial commands.

Affected

6 ranges
VendorProductVersion rangeFixed in
huaweiar_firmware
huaweiar_firmware
huaweiar_firmware
huaweinetengine_16ex_firmware
huaweinetengine_16ex_firmware
huaweinetengine_16ex_firmware

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.