CVE-2015-8228
Summary
| CVE | CVE-2015-8228 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-11-24 20:59:21 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 routers with software before V200R006SPH003 allows remote authenticated users to access arbitrary directories via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Ar120 | All | All | All | All |
| Hardware | Huawei | Ar1200 | All | All | All | All |
| Hardware | Huawei | Ar150 | All | All | All | All |
| Hardware | Huawei | Ar160 | All | All | All | All |
| Hardware | Huawei | Ar200 | All | All | All | All |
| Hardware | Huawei | Ar2200 | All | All | All | All |
| Hardware | Huawei | Ar3200 | All | All | All | All |
| Hardware | Huawei | Ar3600 | All | All | All | All |
| Hardware | Huawei | Ar500 | All | All | All | All |
| Operating System | Huawei | Ar Firmware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Directory Traversal Vulnerability in Huawei AR Router | af854a3a-2127-422b-91ae-364da2661108 | www1.huawei.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 43847 Huawei Router Directory Traversal Vulnerability (HW-461676)