CVE-2017-2736: Huawei VCM5010 Firmware

High severity, CVSS 7.2. EPSS: 1.4% chance of exploitation in the next 30 days.

VCM5010 with software versions earlier before V100R002C50SPC100 has a command injection vulnerability. This is due to insufficient validation of user's input. An authenticated attacker could launch a command injection attack.

Affected products

  • Huawei VCM5010 Firmware: before v100r002c50spc100 (fixed in v100r002c50spc100)

Published 2017-11-22. Last modified 2026-06-17.