CVE-2020-9199
Status: ModifiedMedium (6.8)—
B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the LAN. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject commands to the target device.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Base score: 6.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.80%
- Percentile among all scored CVEs: 55
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (3)
CWEs
- CWE-77
References
Raw JSON (NVD)
Show
{
"id": "CVE-2020-9199",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.7,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 5.1,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "psirt@huawei.com",
"affectedData": [
{
"vendor": "n/a",
"product": "B2368-22;B2368-57;B2368-66",
"versions": [
{
"status": "affected",
"version": "V100R001C00"
}
]
}
]
}
],
"published": "2020-09-03T18:15:15.223",
"references": [
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200902-01-command-en",
"tags": [
"Vendor Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200902-01-command-en",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the LAN. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to inject commands to the target device."
},
{
"lang": "es",
"value": "B2368-22 versión V100R001C00; B2368-57 versión V100R001C00; B2368-66 versión V100R001C00, presentan una vulnerabilidad de inyección de comando. Un atacante con privilegios elevados puede explotar esta vulnerabilidad mediante algunas operaciones en la LAN. Debido a una comprobación de entrada insuficiente de algunos parámetros, el atacante puede explotar esta vulnerabilidad para inyectar comandos en el dispositivo objetivo"
}
],
"lastModified": "2026-06-17T03:27:34.193",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:b2368-22_firmware:v100r001c00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F352301-16EA-48A3-B8FF-80E0B39343BD"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:b2368-22:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C9F144A2-2B30-4674-B66D-A50948593434"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:b2368-57_firmware:v100r001c00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B66FA48B-331C-4F4E-BDB2-7D5978A5C148"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:b2368-57:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "78D8ADD6-FACC-4F26-ABC3-EB6A530C8456"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:b2368-66_firmware:v100r001c00:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA175370-603E-4A4E-89EF-8AF37788614A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:b2368-66:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "62A7FE7C-1ADC-4A64-9F53-78FEE0622CA6"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@huawei.com"
}