Vulnerabilities > Huawei > Critical

DATE CVE VULNERABILITY TITLE RISK
2014-12-03 CVE-2014-9134 Unspecified vulnerability in Huawei products
Unrestricted file upload vulnerability in Huawei Honor Cube Wireless Router WS860s before V100R001C02B222 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.
network
low complexity
huawei
critical
10.0
2013-06-20 CVE-2013-4633 Permissions, Privileges, and Access Controls vulnerability in Huawei Seco Versatile Security Manager V200R002C00/V200R002C00Spc100/V200R002C00Spc200
Huawei Seco Versatile Security Manager (VSM) before V200R002C00SPC300 allows remote authenticated users to gain privileges via a certain change to a group configuration setting.
network
low complexity
huawei CWE-264
critical
9.0
2013-06-20 CVE-2012-6570 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Huawei products
The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows remote HTTP servers to conduct heap-based buffer overflow attacks and execute arbitrary code via a crafted response.
network
low complexity
huawei CWE-119
critical
10.0
2013-06-20 CVE-2012-6569 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Huawei products
Stack-based buffer overflow in the HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches allows remote attackers to execute arbitrary code via a long URI.
network
huawei CWE-119
critical
9.3
2009-07-01 CVE-2009-2271 Credentials Management vulnerability in Huawei D100
The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a default password of admin for the admin account in the telnet interface; which makes it easier for remote attackers to obtain access.
network
low complexity
huawei CWE-255
critical
10.0