CVE-2009-2274: Infoleak
The Huawei D100 allows remote attackers to obtain sensitive information via a direct request to (1) lanstatusadv.asp, (2) wlanbasiccfg.asp, or (3) lancfg.asp in en/, related to use of JavaScript to protect against reading file contents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2274?
CVE-2009-2274 has been classified with a moderate severity level as it allows remote attackers to access sensitive information.
How do I fix CVE-2009-2274?
To mitigate CVE-2009-2274, users should upgrade the Huawei D100 firmware to the latest version provided by Huawei.
What devices are affected by CVE-2009-2274?
The primary device affected by CVE-2009-2274 is the Huawei D100 broadband router.
What kind of information can be exposed due to CVE-2009-2274?
CVE-2009-2274 can expose sensitive configuration information, such as LAN and WLAN settings, to remote attackers.
Is CVE-2009-2274 still a threat?
While CVE-2009-2274 was reported in 2009, devices that have not been updated may still be susceptible to this vulnerability.