CVE-2017-15310

MEDIUM

Huawei iReader < 8.0.2.301 - Arbitrary File Deletion via Input Validation Bypass

Title source: llm
STIX 2.1

Description

Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploit this vulnerability to delete specific files from the SD card.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-20
Status published
Products (2)
huawei/ireader < 8.0.2.301
Huawei Technologies Co., Ltd./iReader before 8.0.2.301
Published Dec 22, 2017
Tracked Since Feb 18, 2026