CVE-2014-9694
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 and earlier versions, Tecal RH2268 V2 V100R002C00, Tecal RH2288 V2 V100R002C00SPC117 and earlier versions, Tecal RH2288H V2 V100R002C00SPC115 and earlier versions, Tecal RH2485 V2 V100R002C00SPC502 and earlier versions, Tecal RH5885 V2 V100R001C02SPC109 and earlier versions, Tecal RH5885 V3 V100R003C01SPC102 and earlier versions, Tecal RH5885H V3 V100R003C00SPC102 and earlier versions, Tecal XH310 V2 V100R001C00SPC110 and earlier versions, Tecal XH311 V2 V100R001C00SPC110 and earlier versions, Tecal XH320 V2 V100R001C00SPC110 and earlier versions, Tecal XH621 V2 V100R001C00SPC106 and earlier versions, Tecal DH310 V2 V100R001C00SPC110 and earlier versions, Tecal DH320 V2 V100R001C00SPC106 and earlier versions, Tecal DH620 V2 V100R001C00SPC106 and earlier versions, Tecal DH621 V2 V100R001C00SPC107 and earlier versions, Tecal DH628 V2 V100R001C00SPC107 and earlier versions, Tecal BH620 V2 V100R002C00SPC107 and earlier versions, Tecal BH621 V2 V100R002C00SPC106 and earlier versions, Tecal BH622 V2 V100R002C00SPC110 and earlier versions, Tecal BH640 V2 V100R002C00SPC108 and earlier versions, Tecal CH121 V100R001C00SPC180 and earlier versions, Tecal CH140 V100R001C00SPC110 and earlier versions, Tecal CH220 V100R001C00SPC180 and earlier versions, Tecal CH221 V100R001C00SPC180 and earlier versions, Tecal CH222 V100R002C00SPC180 and earlier versions, Tecal CH240 V100R001C00SPC180 and earlier versions, Tecal CH242 V100R001C00SPC180 and earlier versions, Tecal CH242 V3 V100R001C00SPC110 and earlier versions have a CSRF vulnerability. The products do not use the Token mechanism for web access control. When users log in to the Huawei servers and access websites containing the malicious CSRF script, the CSRF script is executed, which may cause configuration tampering and system restart.
Huawei Tecal RH1288 V2 V100R002C00SPC107 y versiones anteriores, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 y versiones anteriores, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 y versiones anteriores, Tecal RH2268 V2 V100R002C00, Tecal RH2288 V2 V100R002C00SPC117 y versiones anteriores, Tecal RH2288H V2 V100R002C00SPC115 y versiones anteriores, Tecal RH2485 V2 V100R002C00SPC502 y versiones anteriores, Tecal RH5885 V2 V100R001C02SPC109 y versiones anteriores, Tecal RH5885 V3 V100R003C01SPC102 y versiones anteriores, Tecal RH5885H V3 V100R003C00SPC102 y versiones anteriores, Tecal XH310 V2 V100R001C00SPC110 y versiones anteriores, Tecal XH311 V2 V100R001C00SPC110 y versiones anteriores, Tecal XH320 V2 V100R001C00SPC110 y versiones anteriores, Tecal XH621 V2 V100R001C00SPC106 y versiones anteriores, Tecal DH310 V2 V100R001C00SPC110 y versiones anteriores, Tecal DH320 V2 V100R001C00SPC106 y versiones anteriores, Tecal DH620 V2 V100R001C00SPC106 y versiones anteriores, Tecal DH621 V2 V100R001C00SPC107 y versiones anteriores, Tecal DH628 V2 V100R001C00SPC107 y versiones anteriores, Tecal BH620 V2 V100R002C00SPC107 y versiones anteriores, Tecal BH621 V2 V100R002C00SPC106 y versiones anteriores, Tecal BH622 V2 V100R002C00SPC110 y versiones anteriores, Tecal BH640 V2 V100R002C00SPC108 y versiones anteriores, Tecal CH121 V100R001C00SPC180 y versiones anteriores, Tecal CH140 V100R001C00SPC110 y versiones anteriores, Tecal CH220 V100R001C00SPC180 y versiones anteriores, Tecal CH221 V100R001C00SPC180 y versiones anteriores, Tecal CH222 V100R002C00SPC180 y versiones anteriores, Tecal CH240 V100R001C00SPC180 y versiones anteriores, Tecal CH242 V100R001C00SPC180 y versiones anteriores, Tecal CH242 V3 V100R001C00SPC110 y versiones anteriores tienen una vulnerabilidad de CSRF. Los productos no utilizan el mecanismo Token para el control de acceso web. Cuando los usuarios inician sesión en los servidores Huawei y acceden a los sitios web que contiene la secuencias de comandos CSRF malicioso, se ejecuta la secuencia de comandos CSRF, lo que puede causar manipulación de la configuración y reinicio del sistema.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-03-13 CVE Reserved
- 2017-04-02 CVE Published
- 2023-12-14 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/hw-408100 | 2017-04-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Tecal Rh1288 V2 Firmware Search vendor "Huawei" for product "Tecal Rh1288 V2 Firmware" | <= v100r002c00spc107 Search vendor "Huawei" for product "Tecal Rh1288 V2 Firmware" and version " <= v100r002c00spc107" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh1288 V2 Search vendor "Huawei" for product "Tecal Rh1288 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Rh2265 V2 Firmware Search vendor "Huawei" for product "Tecal Rh2265 V2 Firmware" | v100r002c00 Search vendor "Huawei" for product "Tecal Rh2265 V2 Firmware" and version "v100r002c00" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh2265 V2 Search vendor "Huawei" for product "Tecal Rh2265 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Rh2285 V2 Firmware Search vendor "Huawei" for product "Tecal Rh2285 V2 Firmware" | <= v100r002c00spc115 Search vendor "Huawei" for product "Tecal Rh2285 V2 Firmware" and version " <= v100r002c00spc115" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh2285 V2 Search vendor "Huawei" for product "Tecal Rh2285 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Rh2265 V2 Firmware Search vendor "Huawei" for product "Tecal Rh2265 V2 Firmware" | v100r002c00 Search vendor "Huawei" for product "Tecal Rh2265 V2 Firmware" and version "v100r002c00" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh2265 V2 Search vendor "Huawei" for product "Tecal Rh2265 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Rh2285h V2 Firmware Search vendor "Huawei" for product "Tecal Rh2285h V2 Firmware" | <= v100r002c00spc111 Search vendor "Huawei" for product "Tecal Rh2285h V2 Firmware" and version " <= v100r002c00spc111" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh2285h V2 Search vendor "Huawei" for product "Tecal Rh2285h V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Rh2268 V2 Firmware Search vendor "Huawei" for product "Tecal Rh2268 V2 Firmware" | v100r002c00 Search vendor "Huawei" for product "Tecal Rh2268 V2 Firmware" and version "v100r002c00" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh2268 V2 Search vendor "Huawei" for product "Tecal Rh2268 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Rh2288 V2 Firmware Search vendor "Huawei" for product "Tecal Rh2288 V2 Firmware" | <= v100r002c00spc117 Search vendor "Huawei" for product "Tecal Rh2288 V2 Firmware" and version " <= v100r002c00spc117" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh2288 V2 Search vendor "Huawei" for product "Tecal Rh2288 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Rh2288h V2 Firmware Search vendor "Huawei" for product "Tecal Rh2288h V2 Firmware" | <= v100r002c00spc115 Search vendor "Huawei" for product "Tecal Rh2288h V2 Firmware" and version " <= v100r002c00spc115" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh2288h V2 Search vendor "Huawei" for product "Tecal Rh2288h V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Rh2485 V2 Firmware Search vendor "Huawei" for product "Tecal Rh2485 V2 Firmware" | <= v100r002c00spc502 Search vendor "Huawei" for product "Tecal Rh2485 V2 Firmware" and version " <= v100r002c00spc502" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh2485 V2 Search vendor "Huawei" for product "Tecal Rh2485 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Rh5885 V2 Firmware Search vendor "Huawei" for product "Tecal Rh5885 V2 Firmware" | <= v100r001c02spc109 Search vendor "Huawei" for product "Tecal Rh5885 V2 Firmware" and version " <= v100r001c02spc109" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh5885 V2 Search vendor "Huawei" for product "Tecal Rh5885 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Rh5885 V3 Firmware Search vendor "Huawei" for product "Tecal Rh5885 V3 Firmware" | <= v100r003c01spc102 Search vendor "Huawei" for product "Tecal Rh5885 V3 Firmware" and version " <= v100r003c01spc102" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh5885 V3 Search vendor "Huawei" for product "Tecal Rh5885 V3" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Rh5885h V3 Firmware Search vendor "Huawei" for product "Tecal Rh5885h V3 Firmware" | <= v100r003c00spc102 Search vendor "Huawei" for product "Tecal Rh5885h V3 Firmware" and version " <= v100r003c00spc102" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Rh5885h V3 Search vendor "Huawei" for product "Tecal Rh5885h V3" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Xh310 V2 Firmware Search vendor "Huawei" for product "Tecal Xh310 V2 Firmware" | <= v100r001c00spc110 Search vendor "Huawei" for product "Tecal Xh310 V2 Firmware" and version " <= v100r001c00spc110" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Xh310 V2 Search vendor "Huawei" for product "Tecal Xh310 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Xh311 V2 Firmware Search vendor "Huawei" for product "Tecal Xh311 V2 Firmware" | <= v100r001c00spc110 Search vendor "Huawei" for product "Tecal Xh311 V2 Firmware" and version " <= v100r001c00spc110" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Xh311 V2 Search vendor "Huawei" for product "Tecal Xh311 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Xh320 V2 Firmware Search vendor "Huawei" for product "Tecal Xh320 V2 Firmware" | <= v100r001c00spc110 Search vendor "Huawei" for product "Tecal Xh320 V2 Firmware" and version " <= v100r001c00spc110" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Xh320 V2 Search vendor "Huawei" for product "Tecal Xh320 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Xh621 V2 Firmware Search vendor "Huawei" for product "Tecal Xh621 V2 Firmware" | <= v100r001c00spc106 Search vendor "Huawei" for product "Tecal Xh621 V2 Firmware" and version " <= v100r001c00spc106" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Xh621 V2 Search vendor "Huawei" for product "Tecal Xh621 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Dh310 V2 Firmware Search vendor "Huawei" for product "Tecal Dh310 V2 Firmware" | <= v100r001c00spc110 Search vendor "Huawei" for product "Tecal Dh310 V2 Firmware" and version " <= v100r001c00spc110" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Dh310 V2 Search vendor "Huawei" for product "Tecal Dh310 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Dh320 V2 Firmware Search vendor "Huawei" for product "Tecal Dh320 V2 Firmware" | <= v100r001c00spc106 Search vendor "Huawei" for product "Tecal Dh320 V2 Firmware" and version " <= v100r001c00spc106" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Dh320 V2 Search vendor "Huawei" for product "Tecal Dh320 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Dh620 V2 Firmware Search vendor "Huawei" for product "Tecal Dh620 V2 Firmware" | <= v100r001c00spc106 Search vendor "Huawei" for product "Tecal Dh620 V2 Firmware" and version " <= v100r001c00spc106" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Dh620 V2 Search vendor "Huawei" for product "Tecal Dh620 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Dh621 V2 Firmware Search vendor "Huawei" for product "Tecal Dh621 V2 Firmware" | <= v100r001c00spc107 Search vendor "Huawei" for product "Tecal Dh621 V2 Firmware" and version " <= v100r001c00spc107" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Dh621 V2 Search vendor "Huawei" for product "Tecal Dh621 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Dh628 V2 Firmware Search vendor "Huawei" for product "Tecal Dh628 V2 Firmware" | <= v100r001c00spc107 Search vendor "Huawei" for product "Tecal Dh628 V2 Firmware" and version " <= v100r001c00spc107" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Dh628 V2 Search vendor "Huawei" for product "Tecal Dh628 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Bh620 V2 Firmware Search vendor "Huawei" for product "Tecal Bh620 V2 Firmware" | <= v100r002c00spc107 Search vendor "Huawei" for product "Tecal Bh620 V2 Firmware" and version " <= v100r002c00spc107" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Bh620 V2 Search vendor "Huawei" for product "Tecal Bh620 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Bh621 V2 Firmware Search vendor "Huawei" for product "Tecal Bh621 V2 Firmware" | <= v100r002c00spc106 Search vendor "Huawei" for product "Tecal Bh621 V2 Firmware" and version " <= v100r002c00spc106" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Bh621 V2 Search vendor "Huawei" for product "Tecal Bh621 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Bh622 V2 Firmware Search vendor "Huawei" for product "Tecal Bh622 V2 Firmware" | <= v100r002c00spc110 Search vendor "Huawei" for product "Tecal Bh622 V2 Firmware" and version " <= v100r002c00spc110" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Bh622 V2 Search vendor "Huawei" for product "Tecal Bh622 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Bh640 V2 Firmware Search vendor "Huawei" for product "Tecal Bh640 V2 Firmware" | <= v100r002c00spc108 Search vendor "Huawei" for product "Tecal Bh640 V2 Firmware" and version " <= v100r002c00spc108" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Bh640 V2 Search vendor "Huawei" for product "Tecal Bh640 V2" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Ch121 Firmware Search vendor "Huawei" for product "Tecal Ch121 Firmware" | <= v100r001c00spc180 Search vendor "Huawei" for product "Tecal Ch121 Firmware" and version " <= v100r001c00spc180" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Ch121 Search vendor "Huawei" for product "Tecal Ch121" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Ch140 Firmware Search vendor "Huawei" for product "Tecal Ch140 Firmware" | <= v100r001c00spc110 Search vendor "Huawei" for product "Tecal Ch140 Firmware" and version " <= v100r001c00spc110" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Ch140 Search vendor "Huawei" for product "Tecal Ch140" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Ch220 Firmware Search vendor "Huawei" for product "Tecal Ch220 Firmware" | <= v100r001c00spc180 Search vendor "Huawei" for product "Tecal Ch220 Firmware" and version " <= v100r001c00spc180" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Ch220 Search vendor "Huawei" for product "Tecal Ch220" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Ch221 Firmware Search vendor "Huawei" for product "Tecal Ch221 Firmware" | <= v100r001c00spc180 Search vendor "Huawei" for product "Tecal Ch221 Firmware" and version " <= v100r001c00spc180" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Ch221 Search vendor "Huawei" for product "Tecal Ch221" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Ch222 Firmware Search vendor "Huawei" for product "Tecal Ch222 Firmware" | <= v100r002c00spc180 Search vendor "Huawei" for product "Tecal Ch222 Firmware" and version " <= v100r002c00spc180" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Ch222 Search vendor "Huawei" for product "Tecal Ch222" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Ch240 Firmware Search vendor "Huawei" for product "Tecal Ch240 Firmware" | <= v100r001c00spc180 Search vendor "Huawei" for product "Tecal Ch240 Firmware" and version " <= v100r001c00spc180" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Ch240 Search vendor "Huawei" for product "Tecal Ch240" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Ch242 Firmware Search vendor "Huawei" for product "Tecal Ch242 Firmware" | <= v100r001c00spc180 Search vendor "Huawei" for product "Tecal Ch242 Firmware" and version " <= v100r001c00spc180" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Ch242 Search vendor "Huawei" for product "Tecal Ch242" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Tecal Ch242 V3 Firmware Search vendor "Huawei" for product "Tecal Ch242 V3 Firmware" | <= v100r001c00spc110 Search vendor "Huawei" for product "Tecal Ch242 V3 Firmware" and version " <= v100r001c00spc110" | - |
Affected
| in | Huawei Search vendor "Huawei" | Tecal Ch242 V3 Search vendor "Huawei" for product "Tecal Ch242 V3" | - | - |
Safe
|