CVE-2014-9137: Huawei Fusionmanager

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SPC900 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.

Affected products

  • Huawei Fusionmanager: version v100r002c03 only; version v100r003c00 only
  • Huawei USG2100 Firmware: up to and including v300r001c00spc900
  • Huawei USG2200 Firmware: up to and including v300r001c00spc900
  • Huawei USG5100 Firmware: up to and including v300r001c00spc900
  • Huawei USG5500 Firmware: up to and including v300r001c00spc900
  • Huawei USG9500 Firmware: up to and including v200r001c01spc800; version v300r001c00 only

Published 2017-04-02. Last modified 2026-06-17.