CVE-2016-4577: Huawei Ngfw Module Firmware

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."

Affected products

  • Huawei Ngfw Module Firmware: version v500r001c00 only
  • Huawei Secospace USG6300 Firmware: version v500r001c00 only
  • Huawei Secospace USG6500 Firmware: version v500r001c00 only
  • Huawei Secospace USG6600 Firmware: version v500r001c00 only
  • Huawei USG9500 Firmware: version v500r001c00 only

Published 2016-05-23. Last modified 2026-06-17.