Back

CVE-2017-2738

CRITICAL

VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability. This is due to improper implementation of authentication for accessing web pages. An unauthenticated attacker could bypass the authentication by sending a crafted HTTP request. 5010 with software versions earlier before V100R002C50SPC100 has an arbitrary file upload vulnerability. The software does not validate the files that uploaded. An authenticated attacker could upload arbitrary files to the system.

Published: Nov 22, 2017 Modified: Jun 17, 2026
CWE-287

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
huawei vcm5010_firmware * < v100r002c50spc100

GitHub Security Advisory GHSA-664w-gxq6-68m4

VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 2.69%

Top 15% most likely to be exploited

Threat Score 40 / 100

Data Sources

NVD EPSS GitHub