CVE-2016-6825
Description
Lack of authentication protection in Huawei server firmware allows remote attackers to brute-force passwords for administrative access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Lack of authentication protection in Huawei server firmware allows remote attackers to brute-force passwords for administrative access.
Vulnerability
Huawei XH620 V3, XH622 V3, XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software before V100R003C00SPC617, and RH2288H V3 servers with software before V100R003C00SPC515, as well as CH242 V3 servers with software before V100R001C00SPC285, contain a vulnerability where the management interface lacks authentication protection mechanisms [1]. This shortcoming permits an attacker to perform unlimited login attempts without rate limiting or account lockout, enabling brute-force attacks on user passwords.
Exploitation
An attacker with network access to the affected server's management interface can attempt to log in repeatedly using systematically generated passwords [1]. No prior authentication or special privileges are required. The absence of rate limiting or lockout allows the attacker to try thousands of credential combinations until successful authentication is achieved.
Impact
Successful exploitation grants the attacker valid user credentials, leading to full administrative control over the server [1]. This enables complete compromise of confidentiality, integrity, and availability of the system and any data it processes.
Mitigation
Huawei released fixed firmware versions: V100R003C00SPC610 for XH620/622/628 V3, V100R003C00SPC613 for RH1288 V3, V100R003C00SPC617 for RH2288 V3, V100R003C00SPC515 for RH2288H V3, and V100R001C00SPC285 for CH242 V3 [1]. Users should upgrade to these or later versions. No workaround other than restricting network access to the management interface is documented. The vulnerability is not listed on CISA’s Known Exploited Vulnerabilities catalog as of the available data.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: < V100R003C00SPC610
- Range: < V100R003C00SPC613
- Range: < V100R003C00SPC617
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.huawei.com/en/psirt/security-advisories/huawei-sa-20160817-01-server-ennvdVendor Advisory
- www.securityfocus.com/bid/92504nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.