First published: Thu May 24 2018(Updated: )
Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Due to insufficient verification of the input, this could be exploited to obtain the management privilege of the system.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei 1288h V5 Firmware | =v100r005c00 | |
Huawei 1288H V5 | ||
Huawei 2288h V5 Firmware | =v100r005c00 | |
Huawei 2288h V5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.