CVE-2020-1860: Huawei NIP6800 Firmware

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an access control bypass vulnerability. Attackers that can access to the internal network can exploit this vulnerability with careful deployment. Successful exploit may cause the access control to be bypassed, and attackers can directly access the Internet.

Affected products

  • Huawei NIP6800 Firmware: version v500r001c30 only; version v500r001c60 only; version v500r005c00 only
  • Huawei Secospace USG6600 Firmware: version v500r001c30 only; version v500r001c60 only; version v500r005c00 only
  • Huawei USG9500 Firmware: version v500r001c30 only; version v500r001c60 only; version v500r005c00 only

Published 2020-02-28. Last modified 2026-06-17.