First published: Fri Dec 27 2024(Updated: )
There is a buffer error vulnerability in some Huawei product. An unauthenticated attacker may send special UPNP message to the affected products. Due to insufficient input validation of some value, successful exploit may cause some service abnormal. (Vulnerability ID: HWPSIRT-2017-08234) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9086.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Huawei B612 | =b612s-25dtcpu-v100r001b192d03sp00c234 | |
Huawei B612 | =b612s-25dtcpu-v100r001b192d03sp00c287 | |
Huawei B612 | =b612s-25dtcpu-v100r001b192d05sp00c00 | |
Huawei B612 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9086 is considered to be a moderate severity vulnerability due to its potential to cause service disruption.
To fix CVE-2020-9086, update the affected Huawei B612 firmware to the latest version provided by Huawei.
CVE-2020-9086 affects specific versions of Huawei B612 firmware including b612s-25dtcpu-v100r001b192d03sp00c234, b612s-25dtcpu-v100r001b192d03sp00c287, and b612s-25dtcpu-v100r001b192d05sp00c00.
CVE-2020-9086 can be exploited by unauthenticated attackers who send specially crafted UPNP messages.
Exploitation of CVE-2020-9086 may lead to abnormal service behavior on affected Huawei devices.