PT-2015-7750 · Huawei · Huawei Ar Routers+1
Published
2015-11-11
·
Updated
2015-11-25
·
CVE-2015-8228
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Huawei AR routers versions before V200R006SPH003
Description
The issue allows remote authenticated users to access arbitrary directories via unspecified vectors, potentially leading to information leaks. An attacker can log in to the router and traverse FTP server directories to access unauthorized directories.
Recommendations
For versions before V200R006SPH003, update to V200R006SPH003 or later to resolve the issue. As a temporary workaround, consider restricting access to the SFTP server to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Ar Routers
Huawei Vrp