Huawei E587 CVE-2013-2612 Command Injection Vulnerability
BID:61167
CVE-2013-2612 |Info
Huawei E587 CVE-2013-2612 Command Injection Vulnerability
| Bugtraq ID: | 61167 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2612 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2013 12:00AM |
| Updated: | Jul 15 2013 12:00AM |
| Credit: | Frédéric Basse <basse.frederic () gmail com> |
| Vulnerable: |
Huawei E587 11.203.27 |
| Not Vulnerable: | |
Discussion
Huawei E587 CVE-2013-2612 Command Injection Vulnerability
Huawei E587 is prone to a command-injection vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary shell commands with root privileges in context of the affected device.
Huawei E587 11.203.27 is vulnerable; other versions may also be affected.
Huawei E587 is prone to a command-injection vulnerability because the application fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary shell commands with root privileges in context of the affected device.
Huawei E587 11.203.27 is vulnerable; other versions may also be affected.
Exploit / POC
Huawei E587 CVE-2013-2612 Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Huawei E587 CVE-2013-2612 Command Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Huawei E587 CVE-2013-2612 Command Injection Vulnerability
References:
References:
- [CVE-2013-2612] Huawei E587 3G Mobile Hotspot Command Injection (BugTraq)
- Huawei E587 Homepage (Huawei Technologies)
- Huawei Technologies Homepage (Huawei Technologies)