CVE-2021-22449

HIGH

Elf-G10HN <1.0.0.608 - Privilege Escalation

Title source: llm
STIX 2.1

Description

There is a logic vulnerability in Elf-G10HN 1.0.0.608. An unauthenticated attacker could perform specific operations to exploit this vulnerability. Due to insufficient security design, successful exploit could allow an attacker to add users to be friends without prompting in the target device.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0018
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (1)
huawei/elf-g10hn 1.0.0.608
Published Aug 23, 2021
Tracked Since Feb 18, 2026