First published: Thu May 24 2018(Updated: )
Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Due to insufficient verification of the input, this could be exploited to obtain the management privilege of the system.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei 1288h V5 Firmware | =v100r005c00 | |
Huawei 1288h V5 Firmware | ||
Huawei 2288H V5 | =v100r005c00 | |
Huawei 2288h V5 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7902 has been classified as a high severity vulnerability due to its potential impact on administrator access.
To mitigate CVE-2018-7902, it is recommended to update the Huawei 1288H V5 or 2288H V5 to a patched version of the firmware.
CVE-2018-7902 affects devices running Huawei 1288H V5 and 2288H V5 with firmware version V100R005C00.
CVE-2018-7902 involves a JSON injection attack that can lead to unauthorized password modifications for the administrator.
Yes, CVE-2018-7902 can be exploited by an authenticated remote attacker, making it particularly concerning.