CVE-2019-5260
Description
Huawei smartphones HUAWEI Y9 2019 and Honor View 20 have a denial of service vulnerability. Due to insufficient input validation of specific value when parsing the messages, an attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices to exploit this vulnerability. Successful exploit may cause an infinite loop and the device to reboot.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Insufficient input validation in TD-SCDMA message parsing on Huawei Y9 2019 and Honor View 20 allows a rogue base station to cause denial of service via infinite loop and device reboot.
Vulnerability
CVE-2019-5260 is a denial of service vulnerability in Huawei smartphones HUAWEI Y9 2019 and Honor View 20. The flaw resides in the parsing of TD-SCDMA messages due to insufficient input validation of a specific value. Affected versions include ALP-AL00B 8.0.0.153(C00), ALP-L09 8.0.0.153(C432), and ALP-L29 8.0.0.145(C636) [1].
Exploitation
An attacker must operate a rogue base station within radio range of the target device. No authentication or user interaction is required. The attacker sends specially crafted TD-SCDMA messages to the device. When the device processes these messages, the insufficient validation triggers an infinite loop, causing the device to become unresponsive and reboot [1].
Impact
Successful exploitation results in a denial of service condition. The device enters an infinite loop and reboots, temporarily disrupting service. No data confidentiality or integrity impact is reported [1].
Mitigation
Huawei has released software updates to fix the vulnerability. The resolved versions are: ALP-AL00B 9.1.0.333(C00E333R2P1T8), ALP-L09 9.1.0.300(C432E4R1P9T8), and ALP-L29 9.1.0.315(C…). Users should update their devices to the latest firmware via the official update mechanism. No workaround is available. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.huawei.com/en/psirt/security-advisories/huawei-sa-20190911-01-mobile-enmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.