Plug-in Signature Bypass in Huawei HiRouter and WS5200 Products
CVE-2018-7937

7.8HIGH

Key Information:

Vendor

McAfee

Vendor
CVE Published:
4 September 2018

What is CVE-2018-7937?

A vulnerability exists in Huawei's HiRouter-CD20 and WS5200 products where inadequate verification of plug-ins can lead to a bypass of signature checks. An attacker can exploit this weakness by modifying a legitimate plug-in, thereby packaging it with malicious intent. If a user inadvertently installs this compromised plug-in, the attacker could gain root permissions, allowing for complete control over the device and its functions. This highlights the importance of robust security measures in verifying plug-in integrity to prevent unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

HiRouter-CD20, WS5200-10 The versions before HiRouter-CD20-10 1.9.6, The versions before WS5200-10 1.9.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.