First published: Tue Nov 24 2015(Updated: )
Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 routers with software before V200R006SPH003 allows remote authenticated users to access arbitrary directories via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei AR firmware | <=v200r006c10 | |
Huawei AR120 firmware | ||
Huawei AR1200 | ||
Huawei AR 150 | ||
Huawei AR160 Firmware | ||
Huawei AR200 | ||
Huawei AR2200 Series Firmware | ||
Huawei AR3200 firmware | ||
Huawei AR3600 Firmware | ||
Huawei AR500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8228 is classified as a high severity vulnerability due to its potential for unauthorized directory access.
To fix CVE-2015-8228, you should upgrade your Huawei router firmware to version V200R006SPH003 or later.
CVE-2015-8228 affects various Huawei AR routers including models 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600.
Yes, remote authenticated users can exploit CVE-2015-8228 to access arbitrary directories on the vulnerable devices.
There are no known workarounds for CVE-2015-8228; the best mitigation is to apply the firmware update.