CVE-2016-6824 describes a denial-of-service vulnerability affecting Huawei AC6003, AC6005, AC6605, and ACU2 access controllers running software prior to V200R006C10SPC200. Authenticated attackers can trigger a device restart by sending specially crafted CAPWAP packets. Rated with a CVSS score of 6.5 (Medium), this vulnerability has a network attack vector and low attack complexity, requiring authenticated access to achieve a high impact denial of service. There is no impact on confidentiality or integrity. There is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= v200r005c10CPE matchmatch criteria | cpe:2.3:o:huawei:ac6003_firmware:*:*:*:*:*:*:*:* | ||
<= v200r006c00CPE matchmatch criteria | cpe:2.3:o:huawei:ac6003_firmware:*:*:*:*:*:*:*:* | ||
<= v200r005c10CPE matchmatch criteria | cpe:2.3:o:huawei:ac6005_firmware:*:*:*:*:*:*:*:* | ||
<= v200r006c00CPE matchmatch criteria | cpe:2.3:o:huawei:ac6005_firmware:*:*:*:*:*:*:*:* | ||
<= v200r005c10CPE matchmatch criteria | cpe:2.3:o:huawei:ac6605_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.