CVE-2016-6901
Summary
| CVE | CVE-2016-6901 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-09-26 16:59:08 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR3600 routers with software before V200R007C00SPC900 and NetEngine 16EX routers with software before V200R007C00SPC900 allows remote authenticated users to cause a denial of service via format string specifiers in vectors involving partial commands. |
Risk And Classification
Primary CVSS: v3.0 6.5 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.002330000 probability, percentile 0.460020000 (date 2026-05-07)
Problem Types: CWE-20 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 6.8 | AV:N/AC:L/Au:S/C:N/I:N/A:C |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:S/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Ar100 | - | All | All | All |
| Hardware | Huawei | Ar120 | - | All | All | All |
| Hardware | Huawei | Ar1200 | - | All | All | All |
| Hardware | Huawei | Ar150 | - | All | All | All |
| Hardware | Huawei | Ar200 | - | All | All | All |
| Hardware | Huawei | Ar2200 | - | All | All | All |
| Hardware | Huawei | Ar2500 | - | All | All | All |
| Hardware | Huawei | Ar3200 | - | All | All | All |
| Hardware | Huawei | Ar3600 | - | All | All | All |
| Hardware | Huawei | Ar500 | - | All | All | All |
| Hardware | Huawei | Ar550 | - | All | All | All |
| Operating System | Huawei | Ar Firmware | v200r005 | All | All | All |
| Operating System | Huawei | Ar Firmware | v200r006 | All | All | All |
| Operating System | Huawei | Ar Firmware | v200r007c00 | All | All | All |
| Hardware | Huawei | Netengine 16ex | - | All | All | All |
| Operating System | Huawei | Netengine 16ex Firmware | v200r005 | All | All | All |
| Operating System | Huawei | Netengine 16ex Firmware | v200r006 | All | All | All |
| Operating System | Huawei | Netengine 16ex Firmware | v200r007c00 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Huawei Products CVE-2016-6901 Remote Format String Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| * | af854a3a-2127-422b-91ae-364da2661108 | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 43846 Huawei Router Uncontrolled Format String Vulnerability (HUAWEI-SA-20160824-01-VRP-EN)