CVE-2017-8156
Last modified
CVE-2017-8156 is a vulnerability of currently unknown severity. The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port. An attacker can access the serial port on the circuit board of the outdoor unit and log in to the CPE without authentication. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on the serial port. An attacker can access the serial port on the circuit board of the outdoor unit and log in to the CPE without authentication. Successful exploit could allow the attacker to take control over the outdoor unit.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | B2338-168 Firmware | v100r001c00 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8156?
How severe is CVE-2017-8156?
How do I fix CVE-2017-8156?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-8150The boot loaders of P10 and P10 Plus Huawei mobile phones wi…
- CVE-2017-8151Huawei Honor 5S smart phones with software the versions befo…
- CVE-2017-8152Huawei Honor 5S smart phones with software the versions befo…
- CVE-2017-8153Huawei VMall (for Android) with the versions before 1.5.8.5 …
- CVE-2017-8154The Themes App Honor 8 Lite Huawei mobile phones with softwa…
- CVE-2017-8155The outdoor unit of Customer Premise Equipment (CPE) product…
- CVE-2017-8157OceanStor 5800 V3 with software V300R002C00 and V300R002C10,…
- CVE-2017-8158FusionCompute V100R005C00 and V100R005C10 have an improper a…
- CVE-2017-8159Some Huawei smartphones with software AGS-L09C233B019,AGS-W0…
- CVE-2017-8160The Madapt Driver of some Huawei smart phones with software …
- CVE-2017-8161EVA-L09 smartphones with software Earlier than EVA-L09C25B15…
- CVE-2017-8162AR120-S with software V200R006C10, V200R007C00, V200R008C20,…
Are you affected by CVE-2017-8156?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
