CVE-2022-41579

MEDIUM

Huawei HOTA-FARA-B19 Firmware - Improper Authentication

Title source: llm
STIX 2.1

Description

There is an insufficient authentication vulnerability in some Huawei band products. Successful exploit could allow the attacker to spoof then connect to the band.

Scores

CVSS v3 6.5
EPSS 0.0009
EPSS Percentile 24.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
huawei/hota-fara-b19_firmware 11.1.2.40
Published Dec 28, 2022
Tracked Since Feb 18, 2026