CVE-2018-7933
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Huawei home gateway products HiRouter-CD20 and WS5200 with the versions before HiRouter-CD20-10 1.9.6 and the versions before WS5200-10 1.9.6 have a path traversal vulnerability. Due to the lack of validation while these home gateway products install APK plugins, an attacker tricks a user into installing a malicious APK plugin, and plugin can overwrite arbitrary file of devices. Successful exploit may result in arbitrary code execution or privilege escalation.
Los productos domésticos de gateway Huawei HiRouter-CD20 y WS5200 con versiones anteriores a la HiRouter-CD20-10 1.9.6 y anteriores a la WS5200-10 1.9.6 tienen una vulnerabilidad de salto de directorio. Debido a la falta de validación mientras estos productos domésticos de gateway instalan plugins APK, un atacante engaña a un usuario para que instale un plugin APK malicioso que puede sobrescribir archivos arbitrarios de los dispositivos. La explotación exitosa puede resultar en la ejecución de código arbitrario o el escalado de privilegios.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-09 CVE Reserved
- 2018-05-10 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180502-01-gateway-en | 2018-06-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Hirouter-cd20 Firmware Search vendor "Huawei" for product "Hirouter-cd20 Firmware" | < hirouter-cd20-10_1.9.6 Search vendor "Huawei" for product "Hirouter-cd20 Firmware" and version " < hirouter-cd20-10_1.9.6" | - |
Affected
| in | Huawei Search vendor "Huawei" | Hirouter-cd20 Search vendor "Huawei" for product "Hirouter-cd20" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Ws5200 Firmware Search vendor "Huawei" for product "Ws5200 Firmware" | < ws5200-10_1.9.6 Search vendor "Huawei" for product "Ws5200 Firmware" and version " < ws5200-10_1.9.6" | - |
Affected
| in | Huawei Search vendor "Huawei" | Ws5200 Search vendor "Huawei" for product "Ws5200" | - | - |
Safe
|