CVE-2012-5969: Huawei e585

Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Multiple directory traversal vulnerabilities on the Huawei E585 device allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the PATH_INFO of an sdcard/ request or (2) modify arbitrary files via a .. (dot dot) in the req_page parameter to en/sms.cgi.

Affected products

  • Huawei e585: affected versions not specified
  • Huawei e585u-82: affected versions not specified

Published 2012-12-19. Last modified 2026-06-16.