CVE-2016-6901 describes a format string vulnerability affecting various Huawei AR series and NetEngine 16EX routers running specific software versions. This flaw allows a remote authenticated attacker to trigger a denial of service by injecting format string specifiers into partial commands. Rated Medium severity (CVSS 6.5), it requires authentication but has low attack complexity, leading to high availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v200r005CPE matchmatch criteria | cpe:2.3:o:huawei:ar_firmware:v200r005:*:*:*:*:*:*:* | ||
v200r006CPE matchmatch criteria | cpe:2.3:o:huawei:ar_firmware:v200r006:*:*:*:*:*:*:* | ||
v200r007c00CPE matchmatch criteria | cpe:2.3:o:huawei:ar_firmware:v200r007c00:*:*:*:*:*:*:* | ||
v200r005CPE matchmatch criteria | cpe:2.3:o:huawei:netengine_16ex_firmware:v200r005:*:*:*:*:*:*:* | ||
v200r006CPE matchmatch criteria | cpe:2.3:o:huawei:netengine_16ex_firmware:v200r006:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.