CVE-2013-6031

Published Mar 11, 2014

Last updated 11 years ago

Overview

Description
The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remote attackers to change passwords and settings, or obtain sensitive information, via a direct request to (1) api/wlan/security-settings, (2) api/device/information, (3) api/wlan/basic-settings, (4) api/wlan/mac-filter, (5) api/monitoring/status, or (6) api/dhcp/settings.
Source
cret@cert.org
NVD status
Analyzed

Risk scores

CVSS 2.0

Type
Primary
Base score
4.3
Impact score
4.9
Exploitability score
5.5
Vector string
AV:A/AC:M/Au:N/C:P/I:P/A:N

Weaknesses

nvd@nist.gov
CWE-287

Social media

Hype score
Not currently trending

Configurations