Overview
Huawei HG532 routers, including the HG532e, n, s, and possibly other models, are vulnerable to arbitrary file access through path traversal.
Description
| CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') - CVE-2015-7254 In vulnerable Huawei router models, the /icon/ path of requests to Internet-facing TCP port 37215 can be manipulated to gain access to arbitrary files. For instance, a remote, unauthenticated attacker could read the inittab file by directly requesting http://<target_IP>:37215/icon/../../../etc/inittab. | 
Impact
| A LAN-based attacker can access arbitrary files on vulnerable devices. Note that in some configurations, an external attacker may be able to leverage this vulnerability. | 
Solution
| Apply an update | 
| Restrict access | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 3.3 | AV:A/AC:L/Au:N/C:P/I:N/A:N | 
| Temporal | 2.7 | E:F/RL:OF/RC:C | 
| Environmental | 2.0 | CDP:N/TD:M/CR:ND/IR:ND/AR:ND | 
References
Acknowledgements
Thanks to Roberto Paleari and Aristide Fattori for reporting this vulnerability.
This document was written by Joel Land.
Other Information
| CVE IDs: | CVE-2015-7254 | 
| Date Public: | 2015-11-06 | 
| Date First Published: | 2015-11-06 | 
| Date Last Updated: | 2015-11-09 14:20 UTC | 
| Document Revision: | 20 |