CVE-2020-1785
Description
Mate 10 Pro;Honor V10;Honor 10;Nova 4 smartphones have a denial of service vulnerability. The system does not properly check the status of certain module during certain operations, an attacker should trick the user into installing a malicious application, successful exploit could cause reboot of the smartphone.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A system status check flaw in Huawei smartphones allows a malicious app to trigger a reboot, enabling denial of service via user deception.
Vulnerability
CVE-2020-1785 is a denial of service vulnerability present in Huawei Mate 10 Pro, Honor V10, Honor 10, and Nova 4 smartphones. The system does not properly verify the status of a certain module during specific operations. The affected versions include BLA-L09C, BLA-L29C, and other models earlier than resolved versions such as 9.1.0.321(C605E4R1P13T8) and 9.1.0.330(C432E6R1P12T8). The vulnerability exists because the system fails to check the module's state, allowing a malicious application to exploit this oversight [1].
Exploitation
To exploit this vulnerability, an attacker must trick the user into installing a malicious application. The attacker does not require any special network position or authentication beyond the user's consent to install the app. Once installed, the malicious app triggers the vulnerable operation, causing the system to mishandle the module status and lead to a device reboot [1].
Impact
Successful exploitation results in a denial of service by causing the smartphone to reboot. This is a temporary loss of availability; the attacker does not gain code execution, data access, or persistent control. The impact is limited to disrupting the device's normal operation until it reboots [1].
Mitigation
Huawei has released software updates to fix this vulnerability. Users should upgrade their devices to the resolved versions listed in the advisory, such as 9.1.0.321(C605E4R1P13T8) for BLA-L09C or 9.1.0.330(C432E6R1P12T8) for BLA-L29C. The initial advisory was published on 2020-01-02, with the last update on 2020-09-02. Users should apply the updates via official channels [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
5- Huawei/Mate 10 Prodescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.huawei.com/en/psirt/security-advisories/huawei-sa-20200102-03-smartphone-enmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.