Vulnerability Description
Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Hg532E | - |
| Huawei | Hg532N | - |
| Huawei | Hg532S | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/hw-462908
- http://www.kb.cert.org/vuls/id/438928Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/77506
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/
- https://github.com/0xAdrian/scripts/blob/master/2015_7254_exploit.py
- https://www.exploit-db.com/exploits/45991/
- http://www.huawei.com/en/psirt/security-advisories/hw-462908
- http://www.kb.cert.org/vuls/id/438928Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/77506
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/
- https://github.com/0xAdrian/scripts/blob/master/2015_7254_exploit.py
- https://www.exploit-db.com/exploits/45991/
FAQ
What is CVE-2015-7254?
CVE-2015-7254 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI.
How severe is CVE-2015-7254?
CVE-2015-7254 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-7254?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Hg532E, Huawei Hg532N, Huawei Hg532S.