CVE-2017-8138: Huawei Hedex Lite
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a website containing malicious scripts which may tamper with configurations and interrupt normal services.
Affected products
- Huawei Hedex Lite: before v200r006c00 (fixed in v200r006c00)
Published 2017-11-22. Last modified 2026-06-17.