CVE-2017-17301 describes a critical weak cryptography vulnerability affecting numerous Huawei AR series routers, CloudEngine switches, and other enterprise devices across multiple firmware versions. An unauthenticated remote attacker can exploit this flaw by forging a specific RSA certificate due to improper handling of certificate values. This allows the attacker to bypass authentication, gain unauthorized access, and obtain permissions configured for a specific user. The vulnerability carries a CVSSv3 score of 9.8 (Critical), indicating a severe risk. It has a low attack complexity and requires no user interaction, allowing for complete compromise of confidentiality, integrity, and availability. The weakness stems from CWE-295 (Improper Certificate Validation). Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting a lack of widespread attention or public awareness regarding its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v200r005c32CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r005c32:*:*:*:*:*:*:* | ||
v200r006c10CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r006c10:*:*:*:*:*:*:* | ||
v200r007c00CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r007c00:*:*:*:*:*:*:* | ||
v200r008c20CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r008c20:*:*:*:*:*:*:* | ||
v200r005c20CPE matchmatch criteria | cpe:2.3:o:huawei:ar1200_firmware:v200r005c20:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.