CVE-2019-5269
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Some Huawei home routers have an improper authorization vulnerability. Due to improper authorization of certain programs, an attacker can exploit this vulnerability to execute uploaded malicious files and escalate privilege.
Affected (23)
Products: Huawei: Cd10 10 Firmware, Cd16 10 Firmware, Cd17 10 Firmware, Cd18 10 Firmware, Hirouter Cd15 10 Firmware, Hirouter Cd20 10 Firmware, Hirouter Cd21 16 Firmware, Hirouter Cd30 10 Firmware, Hirouter Cd30 11 Firmware, Hirouter H1 10 Firmware, Tc5200 10 Firmware, Ws5100 10 Firmware, Ws5102 10 Firmware, Ws5106 10 Firmware, Ws5108 10 Firmware, Ws5200 10 Firmware, Ws5200 11 Firmware, Ws5280 10 Firmware, Ws5280 11 Firmware, Ws6500 10 Firmware, Ws6500 11 Firmware, Ws826 10 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.2.2 to 10.0.2.7 |
| Running on/with | Platform Versions |
|---|---|
Huawei Cd10 10 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.2.3 to 10.0.2.5 |
| Running on/with | Platform Versions |
|---|---|
Huawei Cd16 10 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.0.3.3 to 10.0.2.5 |
| Running on/with | Platform Versions |
|---|---|
Huawei Cd17 10 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.0.2.23 to 10.0.2.5 |
| Running on/with | Platform Versions |
|---|---|
Huawei Cd18 10 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.0.2.3 to 10.0.2.5 |
| Running on/with | Platform Versions |
|---|---|
Huawei Hirouter Cd15 10 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.0.3.9 to 10.0.2.6 |
| Running on/with | Platform Versions |
|---|---|
Huawei Hirouter Cd20 10 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.0.3.9 to 10.0.2.5 |
| Running on/with | Platform Versions |
|---|---|
Huawei Hirouter Cd21 16 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.2.8 to 10.0.2.9 |
| Running on/with | Platform Versions |
|---|---|
Huawei Hirouter Cd30 10 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.2.8 to 10.0.2.9 |
| Running on/with | Platform Versions |
|---|---|
Huawei Hirouter Cd30 11 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.0.3.11 to 10.0.2.5 |
| Running on/with | Platform Versions |
|---|---|
Huawei Hirouter H1 10 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.2.3 to 10.0.2.5 |
| Running on/with | Platform Versions |
|---|---|
Huawei Tc5200 10 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.0.3.11 to 10.0.2.7 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ws5100 10 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.2.2 to 10.0.2.7 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ws5102 10 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.2.2 to 10.0.2.7 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ws5106 10 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.2.2 to 10.0.2.7 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ws5108 10 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.0.3.9 to 10.0.2.6 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ws5200 10 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0.2.3 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ws5200 11 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.0.3.22 to 10.0.2.6 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ws5280 10 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.0.3.22 to 10.0.2.6 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ws5280 11 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.2.3 to 10.0.2.5 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ws6500 10 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| From 10.0.2.2 to 10.0.2.7 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ws6500 11 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| From 9.0.3.11 to 10.0.2.5 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ws826 10 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.