CVE-2019-5300

MEDIUM

Huawei Routers - Digital Signature Verification Bypass

Title source: llm
STIX 2.1

Description

There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0001
EPSS Percentile 1.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-347
Status published
Products (50)
huawei/ar1200-s_firmware v200r007c00
huawei/ar1200-s_firmware v200r008c20
huawei/ar1200-s_firmware v200r008c50
huawei/ar1200-s_firmware v200r009c00
huawei/ar1200-s_firmware v200r010c00
huawei/ar1200_firmware v200r007c00
huawei/ar1200_firmware v200r008c20
huawei/ar1200_firmware v200r008c50
huawei/ar1200_firmware v200r009c00
huawei/ar1200_firmware v200r010c00
... and 40 more
Published Jun 04, 2019
Tracked Since Feb 18, 2026