OS Command Injection Vulnerability in EnzoH by Huawei
CVE-2024-58255

5MEDIUM

Key Information:

Vendor

Huawei

Vendor
CVE Published:
8 August 2025

What is CVE-2024-58255?

The EnzoH product from Huawei has introduced an OS command injection vulnerability that allows attackers to execute arbitrary commands on the system. This vulnerability poses a significant risk as it can be exploited by sending specially crafted input to the affected application. When exploited, it can lead to unauthorized actions being performed on behalf of the user, potentially compromising system integrity and confidentiality.

Affected Version(s)

EnzoH-W5611T BIOS 1.07

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-58255 : OS Command Injection Vulnerability in EnzoH by Huawei