CVE-2014-8358 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 5% (pctl 92)
Patch early
A public exploit exists.
Description
Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014) use a weak ACL for the "Mobile Partner" directory, which allows remote attackers to gain SYSTEM privileges by compromising a low privilege account and modifying Mobile Partner.exe.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 5.02% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-426 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-12-11 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| huawei | ec156 |
| huawei | ec156 firmware |
| huawei | ec176 |
| huawei | ec176 firmware |
| huawei | ec177 |
| huawei | ec177 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Huawei Technologies du Mobile Broadband 16.0 - Local Privilege Escalation | 2013-12-24 |
References
- http://www.huawei.com/us/psirt/security-advisories/2014/hw-376152
- http://www.securityfocus.com/bid/70672
- https://packetstormsecurity.com/files/128767/Huawei-Mobile-Partner-DLL-Hijacking.html
- http://www.huawei.com/us/psirt/security-advisories/2014/hw-376152
- http://www.securityfocus.com/bid/70672
- https://packetstormsecurity.com/files/128767/Huawei-Mobile-Partner-DLL-Hijacking.html
→ the Explorer · watch your stack · NVD