CVE-2015-7254
EXPLOITEDHuawei HG532e, HG532n, and HG532s - Path Traversal via Icon URI
Title source: llmExploitation Summary
CVE-2015-7254 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Rebellion.
AI-analyzed exploit summary This exploit targets CVE-2015-7254, a command injection vulnerability in Huawei routers. It leverages a SOAP-based command injection in the DeviceUpgrade_1 endpoint to execute arbitrary commands and retrieve output via a path traversal vulnerability.
Description
Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI.
Exploits (1)
This exploit targets CVE-2015-7254, a command injection vulnerability in Huawei routers. It leverages a SOAP-based command injection in the DeviceUpgrade_1 endpoint to execute arbitrary commands and retrieve output via a path traversal vulnerability.