CVE-2019-5268: Input Validation
Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to obtain files in the device and upload files to some directories.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-5268.
What is the severity of CVE-2019-5268?
The severity of CVE-2019-5268 is high.
Which Huawei home routers are affected by CVE-2019-5268?
Huawei Cd10-10 Firmware, Huawei Cd16-10 Firmware, Huawei Cd17-10 Firmware, Huawei Cd18-10 Firmware, Huawei Hirouter-cd15-10 Firmware, Huawei Hirouter-cd20-10 Firmware, Huawei Hirouter-cd21-16 Firmware, Huawei Hirouter-cd30-10 Firmware, Huawei Hirouter-cd30-11 Firmware, Huawei Hirouter-h1-10 Firmware, Huawei Tc5200-10 Firmware, Huawei Ws5100-10 Firmware, Huawei Ws5102-10 Firmware, Huawei Ws5106-10 Firmware, Huawei Ws5108-10 Firmware, Huawei Ws5200-10 Firmware, Huawei Ws5200-11 Firmware, Huawei Ws5280-10 Firmware, Huawei Ws5280-11 Firmware, Huawei Ws6500-10 Firmware, Huawei Ws6500-11 Firmware, Huawei Ws826-10 Firmware.
How can an attacker exploit CVE-2019-5268?
An attacker can exploit CVE-2019-5268 by sending specially constructed packets to obtain files in the device and upload files to some directories.
Is there a fix available for CVE-2019-5268?
Please refer to the official Huawei security advisory for information on available fixes: http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191113-01-homerouter-en