CVE-2014-9136: Huawei Fusionmanager

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.

Affected products

  • Huawei Fusionmanager: up to and including v100r002c03; up to and including v100r003c00
  • Huawei USG2100 Firmware: up to and including v300r001c00spc900
  • Huawei USG2200 Firmware: up to and including v300r001c00spc900
  • Huawei USG5100 Firmware: up to and including v300r001c00spc900
  • Huawei USG5500 Firmware: up to and including v300r001c00spc900
  • Huawei USG9500 Firmware: up to and including v200r001c01spc800; up to and including v300r001c00

Published 2017-04-02. Last modified 2026-06-17.