First published: Wed Sep 12 2018(Updated: )
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check. An attacker tricks the user who has root privilege to install a crafted application, the application may modify the specific data to exploit the vulnerability. Successful exploit could allow the attacker to execute arbitrary code.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Alp-l09 Firmware | <8.0.0.150\(c432\) | |
Huawei ALP-L09 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-7922.
The severity of CVE-2018-7922 is critical (7.8).
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) are affected by CVE-2018-7922.
An attacker can exploit CVE-2018-7922 by tricking a user with root privilege to install a crafted application, which can then modify specific data.
Yes, updating the Huawei ALP-L09 smart phone to version 8.0.0.150(C432) or later will fix the vulnerability.