First published: Thu May 24 2018(Updated: )
Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Due to insufficient verification of the input, this could be exploited to obtain the management privilege of the system.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei 1288h V5 Firmware | =v100r005c00 | |
Huawei 1288h V5 Firmware | ||
Huawei 2288H V5 | =v100r005c00 | |
Huawei 2288h V5 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7903 is considered a high-severity vulnerability due to its potential to allow unauthorized changes to administrator passwords.
To fix CVE-2018-7903, update the Huawei 1288H V5 and 2288H V5 to the latest firmware version beyond V100R005C00.
CVE-2018-7903 affects Huawei 1288H V5 and 2288H V5 devices running firmware version V100R005C00.
CVE-2018-7903 allows an authenticated remote attacker to perform a JSON injection to modify administrator passwords.
Yes, CVE-2018-7903 involves an authentication mechanism that can be exploited due to insufficient input validation.