Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:36
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.huawei.com/en/psirt/security-advisories/hw-462908 - | |
References | () http://www.kb.cert.org/vuls/id/438928 - Third Party Advisory, US Government Resource | |
References | () http://www.securityfocus.com/bid/77506 - | |
References | () http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-462908.htm - | |
References | () https://github.com/0xAdrian/scripts/blob/master/2015_7254_exploit.py - | |
References | () https://www.exploit-db.com/exploits/45991/ - |
Information
Published : 2015-11-07 03:59
Updated : 2024-11-21 02:36
NVD link : CVE-2015-7254
Mitre link : CVE-2015-7254
CVE.ORG link : CVE-2015-7254
JSON object : View
Products Affected
huawei
- hg532s
- hg532e
- hg532n
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')