This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
Huawei E5332 wireless router has the following two memory overflow vulnerabilities:
Memory overflow occurs when the E5332 Webserver parses a specially crafted HTTP request message, causing the device reboot (Vulnerability ID: HWPSIRT-2014-0861). This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-5327.
Memory overflow occurs when the E5332 Webserver parses a specially crafted Application Programming Interface (API) service request message, causing the device reboot (Vulnerability ID: HWPSIRT-2014-0862). This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-5328.
Product name |
Affected Version |
Resolved Product and Version |
Huawei E5332 Mobile WiFi |
21.344.19.00.1080 |
21.344.27.00.1080 |
By exploiting the vulnerability, the attacker could trigger a memory overflow on the E5332, and cause the reboot of the E5332.
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
Base Score: 5.5 (AV:A/AC:L/Au:S/C:N/I:N/A:C)
Temporal Score: 4.5 (E:F/RL:O/RC:C)1. Prerequisite:
The attacker can be connected to the E5332;
2. Attacking procedure:
Send specially HTTP or API packets to the E5332.
This vulnerability was found by Shuto Imai of Chukyo University. Huawei PSIRT is not aware of any public announcements or malicious use of the vulnerability described in this advisory.
Huawei express our appreciation for Shuto Imai’s concerns on Huawei products.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
2014-10-09 V1.0 INITIAL
None