PT-2015-7750 · Huawei · Huawei Ar Routers+1

Published

2015-11-11

·

Updated

2015-11-25

·

CVE-2015-8228

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Huawei AR routers versions before V200R006SPH003
Description The issue allows remote authenticated users to access arbitrary directories via unspecified vectors, potentially leading to information leaks. An attacker can log in to the router and traverse FTP server directories to access unauthorized directories.
Recommendations For versions before V200R006SPH003, update to V200R006SPH003 or later to resolve the issue. As a temporary workaround, consider restricting access to the SFTP server to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-8228

Affected Products

Huawei Ar Routers
Huawei Vrp