CVE-2019-5300: Medium severity huawei ar1200-s firmware vulnerability
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5300?
CVE-2019-5300 is classified as a high severity vulnerability due to its potential to allow unauthorized access to affected Huawei routers.
How do I fix CVE-2019-5300?
To fix CVE-2019-5300, update the firmware of affected Huawei routers to the latest version provided by Huawei.
Which devices are affected by CVE-2019-5300?
CVE-2019-5300 affects specific models including AR1200, AR150, AR160, AR200, AR2200, AR3200, and several SRG series routers.
What causes the CVE-2019-5300 vulnerability?
The CVE-2019-5300 vulnerability is caused by improper verification of digital signatures for software images in the affected devices.
Is CVE-2019-5300 actively being exploited?
As of now, there have been no confirmed reports of active exploitation of CVE-2019-5300, but it remains a significant security risk.