First published: Sat Apr 05 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the web interface on Huawei Echo Life HG8247 routers with software before V100R006C00SPC127 allows remote attackers to inject arbitrary web script or HTML via an invalid TELNET connection attempt with a crafted username that is not properly handled during construction of the "failed log-in attempts over telnet" log view.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Echo Life | =v1r006c00s120 | |
Huawei Echo Life | =hg8247 | |
All of | ||
Huawei Echo Life | =v1r006c00s120 | |
Huawei Echo Life | =hg8247 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0337 is considered a moderate severity vulnerability due to its potential for exploitation via cross-site scripting.
To fix CVE-2014-0337, update the Huawei Echo Life HG8247 router's firmware to the latest version that addresses this vulnerability.
CVE-2014-0337 facilitates cross-site scripting (XSS) attacks that allow remote attackers to inject arbitrary web scripts or HTML.
CVE-2014-0337 affects Huawei Echo Life HG8247 routers running firmware versions prior to V100R006C00SPC127.
Yes, CVE-2014-0337 can be exploited remotely through an invalid TELNET connection attempt.