Vulnerability record · CVE-2017-17215 · published 20 March 2018
CVE-2017-17215: Huawei HG532 router remote code execution via input validation flaw
Huawei · Hg532 Firmware
Huawei HG532 firmware (including customized versions) fails to properly validate input, allowing an authenticated attacker to send crafted packets to port 37215 and execute arbitrary code. The flaw is remotely reachable and carries a high CVSS score, making it a serious risk for exposed router management interfaces.
Description
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with high CVSS and very high EPSS, though exploitation requires authentication and no KEV listing exists.
What it is
Huawei HG532 firmware (including customized versions) fails to properly validate input, allowing an authenticated attacker to send crafted packets to port 37215 and execute arbitrary code. The flaw is remotely reachable and carries a high CVSS score, making it a serious risk for exposed router management interfaces.
Impact
An attacker who can authenticate can run arbitrary code on the device, gaining full control of the router and potentially pivoting into the connected network.
Attack surface
Reached over the network via port 37215; the CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N), so an attacker needs some level of authentication but no victim action.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.78, 99.5th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the Huawei security notice SN-20171130-01 fix or upgrade to a non-vulnerable firmware version
- Restrict access to port 37215 to trusted management networks only
- Change default credentials and enforce strong authentication on the device
- Disable remote management or WAN-side access to the router interface where not required
- Monitor vendor advisories for updated firmware and reapply patches as released
Detection
- Monitor network traffic to port 37215 for anomalous or malformed packets
- Audit router authentication logs for unexpected logins followed by command execution
- Use IDS/IPS signatures targeting Huawei HG532 exploitation attempts
- Check device firmware versions against the vendor advisory to identify unpatched units
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.huawei.com/en/psirt/security-notices/huawei-sn-20171130-01-hg532-en | MitigationVendor Advisory |
| http://www.securityfocus.com/bid/102344 | Third Party AdvisoryVDB Entry |
| http://www.huawei.com/en/psirt/security-notices/huawei-sn-20171130-01-hg532-en | MitigationVendor Advisory |
| http://www.securityfocus.com/bid/102344 | Third Party AdvisoryVDB Entry |
Track CVE-2017-17215 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-17215), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.