First published: Mon Sep 26 2016(Updated: )
Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR3600 routers with software before V200R007C00SPC900 and NetEngine 16EX routers with software before V200R007C00SPC900 allows remote authenticated users to cause a denial of service via format string specifiers in vectors involving partial commands.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei AR firmware | =v200r005 | |
Huawei AR firmware | =v200r006 | |
Huawei AR firmware | =v200r007c00 | |
Huawei AR100 firmware | ||
Huawei AR120 firmware | ||
Huawei AR1200 | ||
Huawei AR 150 | ||
Huawei AR200 | ||
Huawei AR2200 Series Firmware | ||
Huawei AR2500 | ||
Huawei AR3200 firmware | ||
Huawei AR3600 Firmware | ||
Huawei AR500 | ||
Huawei AR550 | ||
Huawei NetEngine 16EX | =v200r005 | |
Huawei NetEngine 16EX | =v200r006 | |
Huawei NetEngine 16EX | =v200r007c00 | |
Huawei NetEngine 16EX firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6901 is considered a high severity vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2016-6901, update the affected Huawei routers to firmware version V200R007C00SPC900 or later.
CVE-2016-6901 affects multiple Huawei AR series routers and NetEngine 16EX routers running software versions before V200R007C00SPC900.
Yes, CVE-2016-6901 allows remote authenticated users to exploit the vulnerability.
There are currently no specific publicly known exploits targeting CVE-2016-6901, but its denial of service capability poses risks.