First published: Wed Nov 15 2017(Updated: )
VCM5010 with software versions earlier before V100R002C50SPC100 has an arbitrary file upload vulnerability. The software does not validate the files that uploaded. An authenticated attacker could upload arbitrary files to the system.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Vcm5010 Firmware | <v100r002c50spc100 | |
Huawei Vcm5010 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2737 has a medium severity rating due to its potential for arbitrary file uploads by authenticated attackers.
To fix CVE-2017-2737, upgrade the Huawei VCM5010 firmware to version V100R002C50SPC100 or later.
Exploiting CVE-2017-2737 allows an authenticated attacker to upload arbitrary files, which could lead to unauthorized access or system compromise.
CVE-2017-2737 affects Huawei VCM5010 devices running firmware versions earlier than V100R002C50SPC100.
CVE-2017-2737 is specific to the VCM5010 and does not impact other Huawei products or versions not mentioned.