CVE-2018-7907 describes a sensitive information leak vulnerability affecting various Huawei products, including specific models from the Agassi, Baggio2, Bond, Kobe, and Toronto series, among others. An attacker can exploit this by tricking a user into installing a malicious application, leading to the disclosure of sensitive information due to insufficient input verification. This vulnerability has a CVSS v3.0 score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring user interaction, and resulting in high confidentiality impact without affecting integrity or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
ags-l09c100b257custc100d001CPE matchmatch criteria | cpe:2.3:o:huawei:agassi-l09_firmware:ags-l09c100b257custc100d001:*:*:*:*:*:*:* | ||
ags-l09c170b253custc170d001CPE matchmatch criteria | cpe:2.3:o:huawei:agassi-l09_firmware:ags-l09c170b253custc170d001:*:*:*:*:*:*:* | ||
ags-l09c199b251custc199d001CPE matchmatch criteria | cpe:2.3:o:huawei:agassi-l09_firmware:ags-l09c199b251custc199d001:*:*:*:*:*:*:* | ||
ags-l09c229b003custc229d001CPE matchmatch criteria | cpe:2.3:o:huawei:agassi-l09_firmware:ags-l09c229b003custc229d001:*:*:*:*:*:*:* | ||
ags-w09c100b257custc100d001CPE matchmatch criteria | cpe:2.3:o:huawei:agassi-w09_firmware:ags-w09c100b257custc100d001:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.