Vulnerabilities > CVE-2021-22439 - Deserialization of Untrusted Data vulnerability in Huawei Anyoffice V200R006C10

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
huawei
CWE-502
critical

Summary

There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request to exploit this vulnerability. Successfully exploiting this vulnerability, the attacker can execute remote malicious code injection and to control the device.

Vulnerable Configurations

Part Description Count
Application
Huawei
1

Common Weakness Enumeration (CWE)