CVE-2016-6825

Severity CVSS v4.0:
Pending analysis
Type:
CWE-285 Improper Authorization
Publication date:
07/09/2016
Last modified:
12/04/2025

Description

Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, and RH2288H V3 servers with software before V100R003C00SPC515 allow remote attackers to obtain passwords via a brute-force attack, related to "lack of authentication protection mechanisms."

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:rh1288_v3_server_firmware:v100r003c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:rh2288_v3_server_firmware:v100r003c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:rh2288h_v3_server_firmware:v100r003c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:xh620_v3_server_firmware:v100r003c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:xh622_v3_server_firmware:v100r003c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:xh628_v3_server_firmware:v100r003c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:rh1288_v3_server:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:rh2288_v3_server:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:rh2288h_v3_server:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:xh620_v3_server:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:xh622_v3_server:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:xh628_v3_server:-:*:*:*:*:*:*:*