CVE-2017-17309: Huawei HG255S-10 Firmware

High severity, CVSS 7.5. EPSS: 7.3% chance of exploitation in the next 30 days.

Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.

Affected products

  • Huawei HG255S-10 Firmware: version v100r001c163b025sp02 only

Published 2018-06-14. Last modified 2026-06-17.