CVE-2020-1828: Huawei NIP6800 Firmware

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, and V500R005C00 have an input validation vulnerability where the IPSec module does not validate a field in a specific message. Attackers can send specific message to cause out-of-bound read, compromising normal service.

Affected products

  • Huawei NIP6800 Firmware: version v500r001c30 only; version v500r001c60spc500 only; version v500r005c00 only
  • Huawei Secospace USG6600 Firmware: version v500r001c30spc200 only; version v500r001c30spc600 only; version v500r001c60spc500 only; version v500r005c00 only
  • Huawei USG9500 Firmware: version v500r001c30spc200 only; version v500r001c30spc600 only; version v500r001c60spc500 only; version v500r005c00 only

Published 2020-02-17. Last modified 2026-06-17.