CVE-2016-8789
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
02/04/2017
Last modified:
13/05/2026
Description
Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicious scripts to obtain user information or hijack the session, aka XSS.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:espace_integrated_access_device_firmware:v300r001c03:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:espace_integrated_access_device_firmware:v300r001c04:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:espace_integrated_access_device_firmware:v300r001c06:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:espace_integrated_access_device_firmware:v300r001c07:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:espace_integrated_access_device_firmware:v300r001c20:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:espace_integrated_access_device:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



