CVE-2019-5268

HIGH

Huawei Home Router - Info Disclosure

Title source: llm
STIX 2.1

Description

Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to obtain files in the device and upload files to some directories.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0008
EPSS Percentile 23.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-20
Status published
Products (23)
huawei/cd10-10_firmware 10.0.2.2 - 10.0.2.7
huawei/cd16-10_firmware 10.0.2.3 - 10.0.2.5
huawei/cd17-10_firmware 9.0.3.3 - 10.0.2.5
huawei/cd18-10_firmware 9.0.2.23 - 10.0.2.5
huawei/hirouter-cd15-10_firmware 9.0.2.3 - 10.0.2.5
huawei/hirouter-cd20-10_firmware 9.0.3.9 - 10.0.2.6
huawei/hirouter-cd21-16_firmware 9.0.3.9 - 10.0.2.5
huawei/hirouter-cd30-10_firmware 10.0.2.8 - 10.0.2.9
huawei/hirouter-cd30-11_firmware 10.0.2.8 - 10.0.2.9
huawei/hirouter-h1-10_firmware 9.0.3.11 - 10.0.2.5
... and 13 more
Published Nov 29, 2019
Tracked Since Feb 18, 2026