Vulnerability Description
A Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability may allow attackers to gain higher privileges.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ar617Vw Firmware | v300r21c00spc200 |
| Huawei | Ar617Vw | - |
Related Weaknesses (CWE)
References
- https://wr3nchsr.github.io/huawei-netengine-ar617vw-auth-root-rce/ExploitThird Party Advisory
- https://wr3nchsr.github.io/huawei-netengine-ar617vw-auth-root-rce/ExploitThird Party Advisory
FAQ
What is CVE-2022-48616?
CVE-2022-48616 is a vulnerability with a CVSS score of 6.4 (MEDIUM). A Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability may allow attackers to gain higher privileges.
How severe is CVE-2022-48616?
CVE-2022-48616 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-48616?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ar617Vw Firmware, Huawei Ar617Vw.