VYPR
High severity7.2NVD Advisory· Published Nov 22, 2017· Updated May 13, 2026

CVE-2017-2736

CVE-2017-2736

Description

VCM5010 with software versions earlier before V100R002C50SPC100 has a command injection vulnerability. This is due to insufficient validation of user's input. An authenticated attacker could launch a command injection attack.

Affected products

2
  • cpe:2.3:o:huawei:vcm5010_firmware:*:*:*:*:*:*:*:*
    Range: <v100r002c50spc100
  • Huawei Technologies Co., Ltd./VCM5010v5
    Range: Versions earlier before V100R002C50SPC100

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.