CVE-2019-5268Improper Input Validation in Huawei Cd10-10 Firmware

Severity
8.1HIGHNVD
EPSS
0.1%
top 76.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29
Latest updateMay 24

Description

Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to obtain files in the device and upload files to some directories.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages22 packages

NVDhuawei/cd10-10_firmware10.0.2.210.0.2.7
NVDhuawei/cd16-10_firmware10.0.2.310.0.2.5
NVDhuawei/cd17-10_firmware9.0.3.310.0.2.5
NVDhuawei/cd18-10_firmware9.0.2.2310.0.2.5
NVDhuawei/ws826-10_firmware9.0.3.1110.0.2.5

🔴Vulnerability Details

2
GHSA
GHSA-2wp7-476w-v7fh: Some Huawei home routers have an input validation vulnerability2022-05-24
CVEList
CVE-2019-5268: Some Huawei home routers have an input validation vulnerability2019-11-29
CVE-2019-5268 — Improper Input Validation in Huawei | cvebase