CVE-2016-6670: Huawei s7700 Firmware

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-signed certificates, which makes it easier for remote attackers to discover private keys by leveraging knowledge of a certificate.

Affected products

  • Huawei s7700 Firmware: version v200r003c00 only; version v200r005c00 only
  • Huawei s9300 Firmware: version v200r003c00 only; version v200r005c00 only
  • Huawei s9700 Firmware: version v200r003c00 only; version v200r005c00 only
  • Huawei Firmware s12700: version v200r005c00 only

Published 2016-09-07. Last modified 2026-06-17.