First published: Thu May 24 2018(Updated: )
Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Due to insufficient verification of the input, this could be exploited to obtain the management privilege of the system.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei 1288h V5 Firmware | =v100r005c00 | |
Huawei 1288h V5 Firmware | ||
Huawei 2288H V5 | =v100r005c00 | |
Huawei 2288h V5 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7904 has been classified with a high severity level due to the potential for unauthorized password modification.
To mitigate CVE-2018-7904, ensure that your Huawei 1288H V5 and 288H V5 devices are updated to the latest firmware version.
CVE-2018-7904 affects Huawei 1288H V5 and 288H V5 devices running V100R005C00 firmware.
Yes, CVE-2018-7904 can be exploited remotely by an authenticated attacker.
CVE-2018-7904 is a JSON injection vulnerability that allows modification of the administrator password.