CVE-2025-49599

Published Jun 6, 2025

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-49599 affects certain Huawei EG8141A5, EG8145V5, and EG8145V5-V2 devices. Specifically, it allows the "Epuser" account to disable the ONT firewall functionality. This vulnerability makes it possible to remove the default blocking of TCP ports used by SSH and TELNET, potentially exposing these services to unauthorized access.

Description
Huawei EG8141A5 devices through V5R019C00S100, EG8145V5 devices through V5R019C00S100, and EG8145V5-V2 devices through V5R021C00S184 allow the Epuser account to disable ONT firewall functionality, e.g., to remove the default blocking of the SSH and TELNET TCP ports, aka HWNO-56Q3.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.1
Impact score
1.4
Exploitability score
2.3
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Severity
MEDIUM

Weaknesses

cve@mitre.org
CWE-863

Social media

Hype score
Not currently trending