There is a command injection vulnerability in Huawei terminal printer product. Successful exploitation could result in the highest privileges of the printer. (Vulnerability ID: HWPSIRT-2022-51773) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2022-32203.
The vulnerability consists of improper validation of input data, which enables injection of malicious system commands (command injection, CWE-77). An attacker can send specially crafted data to a vulnerable component of the device. The attack vector is network-based, requires no authentication or user interaction, making exploitation exceptionally simple.
An attacker can obtain the highest privileges on the printer device, enabling full control over the device, including configuration modification, reading transmitted data, and potential use of the device as an entry point to the internal network.
Apply patches available from the manufacturer according to the references: https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20220601-01-6b47c6b6-en
Huawei CV81-WDM Firmware and Huawei CV81-WDM — specific versions indicated in manufacturer references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHuawei Cv81 Wdm
HWHuaweiall versionsHuawei Cv81 Wdm Firmware
OSHuawei01.70.49.29.46
Related vulnerabilities
Buffer overflow w Huawei CV81-WDM umożliwiający privilege escalation
There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this v...
There is an improper input verification vulnerability in Huawei printer product. Successful exploitation of th...
Huawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may ca...
There is a denial of service vulnerability in CV81-WDM FW versions 01.70.49.29.46. Successful exploitation cou...