This week, a Trustwave security researcher disclosed a privilege escalation flaw in Huawei’s USB LTE dongles. The vulnerability relies on tampering with the Huawei driver software installed on a computer, making this a case of local privilege escalation. One user, even an unprivileged one, can run code as another user on a multiuser system when the dongle is inserted, such as a password stealer. Trustwave has issued a security advisory and a blog post detailing the vulnerability.
Source: https://www.bleepingcomputer.com/news/security/huawei-usb-lte-dongles-are-vulnerable-to-privilege-escalation-attacks/

