CVE-2018-7933
CVE-2018-7933
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.0%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 May 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Huawei home gateway products HiRouter-CD20 and WS5200 with the versions before HiRouter-CD20-10 1.9.6 and the versions before WS5200-10 1.9.6 have a path traversal vulnerability. Due to the lack of validation while these home gateway products install APK plugins, an attacker tricks a user into installing a malicious APK plugin, and plugin can overwrite arbitrary file of devices. Successful exploit may result in arbitrary code execution or privilege escalation.
Affected products
Huawei Technologies Co., Ltd. · HiRouter-CD20, WS5200Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →