Description
In Huawei HiRouter-CD20-10 with the versions before 1.9.6 and WS5200-10 with the versions before 1.9.6, there is a plug-in signature bypass vulnerability due to insufficient plug-in verification. An attacker may tamper with a legitimate plug-in to build a malicious plug-in and trick users into installing it. Successful exploit could allow the attacker to obtain the root permission of the device and take full control over the device.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-19649 | In Huawei HiRouter-CD20-10 with the versions before 1.9.6 and WS5200-10 with the versions before 1.9.6, there is a plug-in signature bypass vulnerability due to insufficient plug-in verification. An attacker may tamper with a legitimate plug-in to build a malicious plug-in and trick users into installing it. Successful exploit could allow the attacker to obtain the root permission of the device and take full control over the device. |
References
History
No history.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-05T06:37:59.688Z
Reserved: 2018-03-09T00:00:00.000Z
Link: CVE-2018-7937
No data.
Status : Modified
Published: 2018-09-04T16:29:00.753
Modified: 2024-11-21T04:12:59.360
Link: CVE-2018-7937
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD