CVE-2017-17287 is an out-of-bounds read vulnerability affecting numerous Huawei AR series routers and other network devices across multiple software versions. This flaw stems from insufficient input validation, allowing a remote, unauthenticated attacker to send specially crafted signatures. A successful exploit could lead to a buffer overflow, causing services to become abnormal. The vulnerability has a CVSSv3 score of 5.3 (Medium), indicating a network-based attack with low complexity, requiring no privileges or user interaction, and resulting in a loss of availability. While the potential impact is service disruption, there is no direct impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v200r005c32CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r005c32:*:*:*:*:*:*:* | ||
v200r006c10CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r006c10:*:*:*:*:*:*:* | ||
v200r007c00CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r007c00:*:*:*:*:*:*:* | ||
v200r008c20CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r008c20:*:*:*:*:*:*:* | ||
v200r008c30CPE matchmatch criteria | cpe:2.3:o:huawei:ar120-s_firmware:v200r008c30:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.