Vulnerability CVE-2013-2612


Published: 2020-01-27   Modified: 2020-01-28

Description:
Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with root privileges due to an error in the Web UI.

See advisories in our WLB2 database:
Topic
Author
Date
High
Huawei E587 3G Mobile Hotspot Command Injection
Fracdacric Basse
15.07.2013

Type:

CWE-78

(Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') )

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
https://exchange.xforce.ibmcloud.com/vulnerabilities/85782
https://www.securityfocus.com/bid/61167/info

Copyright 2024, cxsecurity.com

 

Back to Top