Vulnerabilities > CVE-2009-2271 - Credentials Management vulnerability in Huawei D100

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
huawei
CWE-255
critical

Summary

The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a default password of admin for the admin account in the telnet interface; which makes it easier for remote attackers to obtain access.

Vulnerable Configurations

Part Description Count
Hardware
Huawei
1

Common Weakness Enumeration (CWE)