{"id": "CVE-2019-5268", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.8, "accessVector": "ADJACENT_NETWORK", "vectorString": "AV:A/AC:L/Au:N/C:P/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 4.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 6.5, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.1, "attackVector": "ADJACENT_NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.2, "exploitabilityScore": 2.8}]}, "published": "2019-11-29T21:15:11.387", "references": [{"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191113-01-homerouter-en", "tags": ["Vendor Advisory"], "source": "psirt@huawei.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-20"}]}], "descriptions": [{"lang": "en", "value": "Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to obtain files in the device and upload files to some directories."}, {"lang": "es", "value": "Algunos enrutadores dom\u00e9sticos de Huawei presentan una vulnerabilidad de comprobaci\u00f3n de entrada. Debido a que el par\u00e1metro de entrada no es verificado correctamente, un atacante puede explotar esta vulnerabilidad mediante el env\u00edo de paquetes especiales construidos para obtener archivos en el dispositivo y cargar archivos en algunos directorios."}], "lastModified": "2019-12-09T19:34:08.653", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:cd10-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E1D1F115-4B8D-498E-A1C0-FB2A99D86314", "versionEndExcluding": "10.0.2.7", "versionStartIncluding": "10.0.2.2"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:cd10-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DB8FC9A3-B7E5-4AC8-8335-1FE9F434A75B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:cd16-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "693353FE-21A4-4A20-B84B-88CD5A94E7C9", "versionEndExcluding": "10.0.2.5", "versionStartIncluding": "10.0.2.3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:cd16-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5E4BF946-F846-4B59-A8BD-71D3C32FA9DE"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:cd17-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F39EBBE2-02F4-49C9-A37E-1A8055A7A29E", "versionEndExcluding": "10.0.2.5", "versionStartIncluding": "9.0.3.3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:cd17-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "86840A12-552E-4673-9459-9C888D311227"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:cd18-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB3D1A03-BF26-49EF-818F-E2605BCE7CA9", "versionEndExcluding": "10.0.2.5", "versionStartIncluding": "9.0.2.23"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:cd18-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C3B85A0E-7A60-464B-BDA0-F62CBB91D469"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:hirouter-cd15-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0EB8D0D-664A-4328-A340-B800D4C4F82F", "versionEndExcluding": "10.0.2.5", "versionStartIncluding": "9.0.2.3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:hirouter-cd15-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F50D5403-BDD7-4733-8EB2-AF960998EC29"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:hirouter-cd20-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D65D593-3B3C-454F-B03D-EA098A66A8D7", "versionEndExcluding": "10.0.2.6", "versionStartIncluding": "9.0.3.9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:hirouter-cd20-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9F964D58-E5DC-459F-8BAE-DC64611C0B1F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:hirouter-cd21-16_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1AE1D8B1-E2E7-430E-892E-8B0CF866E324", "versionEndExcluding": "10.0.2.5", "versionStartIncluding": "9.0.3.9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:hirouter-cd21-16:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "24346A08-F63F-4C1C-9C56-C38CFE951319"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:hirouter-cd30-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E14134F5-65F9-4AA6-B0B0-D0BB29DD236A", "versionEndExcluding": "10.0.2.9", "versionStartIncluding": "10.0.2.8"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:hirouter-cd30-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "593BD59F-41AA-4AEB-8F13-43484BE26E1A"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:hirouter-cd30-11_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "749DBE68-7829-4C8C-8E77-A318A6C069E9", "versionEndExcluding": "10.0.2.9", "versionStartIncluding": "10.0.2.8"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:hirouter-cd30-11:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2A60FDB8-D441-4758-8039-EC72D82129F3"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:hirouter-h1-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C23F869F-205E-4A16-8F39-D2ADE2FC0110", "versionEndExcluding": "10.0.2.5", "versionStartIncluding": "9.0.3.11"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:hirouter-h1-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EFF176F6-C4F5-42C4-8062-944BE659B676"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:tc5200-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7964BB3B-2879-42EB-BFC9-88DA80810424", "versionEndExcluding": "10.0.2.5", "versionStartIncluding": "10.0.2.3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:tc5200-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "677940C5-A53E-400C-A1B1-3AD9E7A5D8A4"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:ws5100-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A5784B9-75DB-4B3C-A39C-BA5981FE59E8", "versionEndExcluding": "10.0.2.7", "versionStartIncluding": "9.0.3.11"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:ws5100-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9047E74D-FCB4-4AC9-AFD4-4671EA894C01"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:ws5102-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB327892-DEFF-46E6-8455-BC46BA9A3618", "versionEndExcluding": "10.0.2.7", "versionStartIncluding": "10.0.2.2"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:ws5102-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1D7CF494-9BFA-4285-B605-F71038D43F3B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:ws5106-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "680447F5-F22A-4CB7-82B2-592F2ABDF1BB", "versionEndExcluding": "10.0.2.7", "versionStartIncluding": "10.0.2.2"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:ws5106-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DB016862-3469-4CD9-BAE5-5E402FEB6F67"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:ws5108-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A92FF02-EDC8-4CA7-B73A-F2EDF16F19FC", "versionEndExcluding": "10.0.2.7", "versionStartIncluding": "10.0.2.2"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:ws5108-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FEEABBD3-61FF-4153-8A74-6EDAAF8139FC"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:ws5200-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D2C5040-4164-4AD5-990C-D0BDBB603CDB", "versionEndExcluding": "10.0.2.6", "versionStartIncluding": "9.0.3.9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:ws5200-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5ABF0A04-286D-41DE-BA82-849C05C8AF28"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:ws5200-11_firmware:9.0.3.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FFD3E480-43D6-4C4C-B87A-D30A4B22A57B"}, {"criteria": "cpe:2.3:o:huawei:ws5200-11_firmware:10.0.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D35B3544-C774-40CD-A1F0-809DE8CAE106"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:ws5200-11:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C907A885-BA32-4819-B53C-0FBFE38C2510"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:ws5280-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B7EAA3A7-B89D-4590-9052-B54725494E71", "versionEndExcluding": "10.0.2.6", "versionStartIncluding": "9.0.3.22"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:ws5280-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2EBF21E5-8CF6-48DA-80ED-58AE59CDA069"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:ws5280-11_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EF2E5FB0-A4E7-49D1-A599-10FB1546EC70", "versionEndExcluding": "10.0.2.6", "versionStartIncluding": "9.0.3.22"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:ws5280-11:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "36E769E6-D560-4E9F-9AC6-93744DAAF051"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:ws6500-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E7A7D72-7B25-44B6-9104-E1C246A87794", "versionEndExcluding": "10.0.2.5", "versionStartIncluding": "10.0.2.3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:ws6500-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8C660061-69B0-43B8-BFD3-E858C6B2B437"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:ws6500-11_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B459C5EE-1F5A-4E23-89CE-E52E8FBB5926", "versionEndExcluding": "10.0.2.7", "versionStartIncluding": "10.0.2.2"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:ws6500-11:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FB0E9103-6DDF-4140-8C60-39B667B982D1"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:ws826-10_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDF101FC-6BD1-48E5-8ADB-B6B9C29F08AE", "versionEndExcluding": "10.0.2.5", "versionStartIncluding": "9.0.3.11"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:ws826-10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F771D83F-8EBA-47E9-9260-C49605EEBCEA"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "psirt@huawei.com"}