CVE-2015-7841 describes a critical command injection vulnerability in the login page of various Huawei FusionServer rack server models, including the RH2288 V3, RH2288H V3, and others, running specific software versions. This flaw allows unauthenticated remote attackers to bypass access restrictions and execute arbitrary commands, such as user creation, through unspecified parameters. With a CVSS v3 score of 9.8 (CRITICAL), the vulnerability has a network attack vector, low attack complexity, and poses a high risk to confidentiality, integrity, and availability. Despite its severity, there is currently no evidence of active exploitation, public exploit code (e.g., Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v100r001c00CPE matchmatch criteria | cpe:2.3:a:huawei:fusionserver_ch121_v3:v100r001c00:*:*:*:*:*:*:* | ||
v100r001c00CPE matchmatch criteria | cpe:2.3:a:huawei:fusionserver_ch220_v3:v100r001c00:*:*:*:*:*:*:* | ||
v100r001c00CPE matchmatch criteria | cpe:2.3:a:huawei:fusionserver_ch222_v3:v100r001c00:*:*:*:*:*:*:* | ||
v100r003c00spc100CPE matchmatch criteria | cpe:2.3:a:huawei:fusionserver_rh1288_v3:v100r003c00spc100:*:*:*:*:*:*:* | ||
v100r002c00CPE matchmatch criteria | cpe:2.3:a:huawei:fusionserver_rh1288a_v2:v100r002c00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.