peter bassill · operator
$ cve CVE-2016-8276 JSON

CVE-2016-8276

9.8
CRITICAL · CVSS 3.0 · EPSS 5.6% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Buffer overflow in the Point-to-Point Protocol over Ethernet (PPPoE) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600, when CHAP authentication is configured on the server, allows remote attackers to cause a denial of service (server restart) or execute arbitrary code via crafted packets sent during authentication.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.61% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2016-10-03
Last modified2026-06-17

Affected (4)

VendorProduct
huaweiusg2100
huaweiusg2200
huaweiusg5100
huaweiusg5500

References

→ the Explorer  ·  watch your stack  ·  NVD