CVE-2014-8358 describes a local privilege escalation vulnerability in Huawei EC156, EC176, and EC177 USB modems with specific software versions. The flaw stems from a weak Access Control List (ACL) on the "Mobile Partner" directory, allowing a remote attacker to gain SYSTEM privileges by compromising a low-privilege account and modifying the Mobile Partner.exe executable. This vulnerability carries a CVSS score of 7.8 (HIGH), indicating a significant impact with high confidentiality, integrity, and availability risks, though it requires user interaction and local access. While not actively exploited in the wild (KEV: No), a public exploit (EDB-30477) exists, yet it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v200r003b009d05sp03c1014CPE matchmatch criteria | cpe:2.3:o:huawei:ec156_firmware:v200r003b009d05sp03c1014:*:*:*:*:*:*:* | ||
v200r003b009d05sp03c1014CPE matchmatch criteria | cpe:2.3:o:huawei:ec176_firmware:v200r003b009d05sp03c1014:*:*:*:*:*:*:* | ||
v200r003b009d05sp03c1014CPE matchmatch criteria | cpe:2.3:o:huawei:ec177_firmware:v200r003b009d05sp03c1014:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.