7.5
CVSSv3

CVE-2014-9690

Published: 02/04/2017 Updated: 05/04/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Huawei home gateways WS318 with software V100R001C01B022 and previous versions versions are affected by the PIN offline brute force cracking vulnerability of the WPS protocol because the random number generator (RNG) used in the supplier's solution is not random enough. As a result, brute force cracking the PIN code is easier. After an attacker cracks the PIN, the attacker can access the Internet via the cracked device.

Vulnerable Product Search on Vulmon Subscribe to Product

huawei ws318_firmware

Github Repositories

WPS PIN Offline Brute Force Cracking Vulnerability in Huawei Home Gateway Products

CVE-2014-9690 WPS PIN Offline Brute Force Cracking Vulnerability in Huawei Home Gateway Products