Command Injection Vulnerability in Huawei Networking Products
CVE-2020-9127
6.7MEDIUM
Key Information:
- Vendor
Huawei
- Vendor
- CVE Published:
- 13 November 2020
What is CVE-2020-9127?
A command injection vulnerability exists in multiple Huawei networking products due to insufficient input validation. This flaw allows a high-privileged attacker to inject malicious commands into specific files, potentially leading to unauthorized access and manipulation of the affected devices. Various models, including the NIP6300, NIP6600, and the Secospace USG series, are affected by this issue, emphasizing the need for immediate patching to mitigate security risks.
Affected Version(s)
NIP6300;NIP6600;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG9500 V500R001C30,V500R001C60