CVE-2020-9122
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
12/10/2020
Last modified:
16/10/2020
Description
Some Huawei products have an insufficient input verification vulnerability. Attackers can exploit this vulnerability in the LAN to cause service abnormal on affected devices.Affected product versions include:HiRouter-CD30-10 version 10.0.2.5;HiRouter-CT31-10 version 10.0.2.20;WS5200-12 version 10.0.1.9;WS5281-10 version 10.0.5.10;WS5800-10 version 10.0.3.25;WS7100-10 version 10.0.5.21;WS7200-10 version 10.0.5.21.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:hirouter-cd30-10_firmware:*:*:*:*:*:*:*:* | 10.0.2.5 (including) | 10.0.5.7 (excluding) |
| cpe:2.3:h:huawei:hirouter-cd30-10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:hirouter-ct31-10_firmware:*:*:*:*:*:*:*:* | 10.0.2.20 (including) | 10.0.2.37 (excluding) |
| cpe:2.3:h:huawei:hirouter-ct31-10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ws5200-12_firmware:*:*:*:*:*:*:*:* | 10.0.1.9 (including) | 10.0.5.6 (including) |
| cpe:2.3:h:huawei:ws5200-12:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ws5281-10_firmware:*:*:*:*:*:*:*:* | 10.0.5.10 (including) | 10.0.5.32 (excluding) |
| cpe:2.3:h:huawei:ws5281-10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ws5800-10_firmware:*:*:*:*:*:*:*:* | 10.0.3.25 (including) | 10.0.3.33 (excluding) |
| cpe:2.3:h:huawei:ws5800-10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ws7100-10_firmware:*:*:*:*:*:*:*:* | 10.0.5.21 (including) | 10.0.5.37 (excluding) |
| cpe:2.3:h:huawei:ws7100-10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ws7200-10_firmware:*:*:*:*:*:*:*:* | 10.0.5.21 (including) | 10.0.5.37 (excluding) |
| cpe:2.3:h:huawei:ws7200-10:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



