This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
Huawei Honor Cube wireless router WS860s supports the file upload function. It allows users to access its files through the web page. As the device is unable to verify every type of file to be uploaded and does not strictly restrict the file access path through the web page, attackers may upload malicious files to the device and execute them, resulting in information leaks and file tampering (Vulnerability ID: HWPSIRT-2014-0946).
This Vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2014-9134
Product Name |
Affected Version |
Resolved Product and Version |
WS860s |
V100R001C02B219 and earlier |
V100R001C02B222 |
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
Base Score: 5.4 (AV:A/AC:M/Au:N/C:P/I:P/A:P)
Temporal Score: 4.5 (E:F/RL:O/RC:C)1.Prerequisite:
Must access the device through a LAN port or using Wi-Fi.
2.Attacking procedure:
Access the device through a LAN port or using Wi-Fi, use the CLI tool on the client to send specific packets to upload a malicious file to an executable directory on the device, and access and execute the file through the web page to obtain the device information, tamper files on the device, or even make the device break down.
For security problems about Huawei products and solutions, please contactPSIRT@huawei.com.
For general problems about Huawei products and solutions, please directly contact Huawei TAC (Huawei Technical Assistance Center) to request the configuration or technical assistance.
2014-11-29 V1.1 UPDATED Added the CVE ID
2014-11-14 V1.0 INITIAL
None