CVE-2017-17215
As of 2024-08-05, CVE-2017-17215 is a CVSS 8.8 (HIGH-severity) vulnerability. Public exploit code available. EPSS exploitation probability 78.6%. Threadlinqs Intelligence tracks 4 threats exploiting it.
Last updated: 2024-08-05
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.
CVSS v3 vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-20
Exploitation status
public exploit code available
- 1337g/CVE-2017-17215 (github)
- wilfred-wulbou/HG532d-RCE-Exploit (github)
- ltfafei/HuaWei_Route_HG532_RCE_CVE-2017-17215 (github)
- trickest/cve (trickest)
Threats tracking this CVE
- TuxBot v3 Evolution: Keksec-Linked IoT/Linux Botnet with Verbatim LLM Chain-of-Thought Code Artifacts — MEDIUM
- TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework With a Broken Multi-CVE Exploit Chain — HIGH
- RustDuck Botnet Rebuilt in Rust with Enhanced C2 Capabilities and Multi-Vector Exploitation — CRITICAL
- P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab Continuous Monitoring) — HIGH
References
- http://www.securityfocus.com/bid/102344
- http://www.huawei.com/en/psirt/security-notices/huawei-sn-20171130-01-hg532-en
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.