CVE-2014-8358
CVE-2014-8358
Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014) use a weak ACL for the "Mobile Partner" directory, which allows remote attackers to gain SYSTEM privileges by compromising a low privilege account and modifying Mobile Partner.exe.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencepacketstormsecurity.com/files/128767/Huawei-Mobile-Partner-DLL-Hijacking.htmlunverifiedexploitdbwww.exploit-db.com/exploits/30477unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →