CVE-2018-7942: Huawei 1288h v5 Firmware

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have an authentication bypass vulnerability. An unauthenticated, remote attacker may send some specially crafted messages to the affected products. Due to improper authentication design, successful exploit may cause some information leak.

Affected products

  • Huawei 1288h v5 Firmware: version 100r005c00 only
  • Huawei 2288h v5 Firmware: version 100r005c00 only
  • Huawei 2488 v5 Firmware: version 100r005c00 only
  • Huawei CH121 v3 Firmware: version 100r001c00 only
  • Huawei CH121L v3 Firmware: version 100r001c00 only
  • Huawei CH121L v5 Firmware: version 100r001c00 only
  • Huawei CH242 v3 Firmware: version 100r001c00 only

Published 2018-05-24. Last modified 2026-06-17.