VYPR
Unrated severityNVD Advisory· Published Feb 15, 2018· Updated Aug 5, 2024

CVE-2017-17186

CVE-2017-17186

Description

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a DoS vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could make some data overwritten, leak device memory and potentially reset a process.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A DoS vulnerability in multiple Huawei products allows authenticated remote attackers to cause data overwrite, memory leak, and process reset via malformed SOAP packets.

Vulnerability

A denial-of-service (DoS) vulnerability exists in Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, and TE60 V100R001C10, V500R002C00, V600R006C00. Due to insufficient input validation, an authenticated remote attacker can send malformed SOAP packets to the target device, leading to data overwrite, memory leak, and potential process reset [1].

Exploitation

An attacker must have valid authentication credentials and network access to the affected device. The attacker sends specially crafted SOAP packets that bypass input validation checks. This triggers memory corruption, causing data overwrite and memory leak, and may reset a process [1].

Impact

Successful exploitation results in denial of service: the device may experience data corruption, memory disclosure, and process crashes, potentially rendering the device unavailable or unstable [1].

Mitigation

Huawei has released software updates to fix this vulnerability. Users should upgrade to the latest firmware versions for their respective products. No workarounds are documented, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Huawei/DP300llm-fuzzy
    Range: V500R002C00
  • Huawei/RP200llm-fuzzy
    Range: V500R002C00, V600R006C00
  • Huawei Technologies Co., Ltd./DP300,RP200,TE30,TE40,TE50,TE60v5
    Range: DP300 V500R002C00, RP200 V500R002C00,V600R006C00, TE30 V100R001C10,V500R002C00,V600R006C00, TE40 V500R002C00,V600R006C00, TE50 V500R002C00,V600R006C00, TE60 V100R001C10,V500R002C00,V600R006C00

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.