VYPR
Unrated severityNVD Advisory· Published Dec 27, 2024· Updated Dec 27, 2024

CVE-2020-9081

CVE-2020-9081

Description

There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An improper authorization vulnerability in Huawei smartphones allows an attacker to bypass the app lock via a series of operations in a specific mode on affected models.

Vulnerability

An improper authorization vulnerability exists in Huawei smartphones, specifically in the app lock functionality. The affected models include HUAWEI Mate 20 (versions earlier than 10.1.0.160(C00E160R3P8) and earlier than 10.1.0.160(C01E160R2P8)) and HUAWEI P30 (versions earlier than 10.1.0.160(C00E160R2P11)), as well as potentially other models listed in the vendor advisory [1]. The vulnerability is triggered when an attacker performs a series of operations in a specific mode, exploiting insufficient authorization checks to bypass the application lock screen.

Exploitation

An attacker needs physical access to the unlocked device or the ability to enter the specific mode (e.g., emergency call or recovery mode). The attacker then executes a sequence of steps (not fully detailed in the public advisory) that leverage the improper authorization to circumvent the app lock mechanism. No additional authentication, network access, or user interaction beyond initial device access is required [1].

Impact

Successful exploitation allows the attacker to bypass the app lock, thereby gaining unauthorized access to protected applications on the device. This leads to potential disclosure of private data (e.g., messages, photos, financial apps) and violates the intended confidentiality protection of the device. The attacker does not gain system-level privileges, but the app lock bypass undermines user privacy [1].

Mitigation

Huawei released software updates to fix this vulnerability on 2020-08-26. Affected users should upgrade to the resolved versions: HUAWEI Mate 20 to 10.1.0.160(C00E160R3P8) or 10.1.0.160(C01E160R2P8); HUAWEI P30 to 10.1.0.160(C00E160R2P11). The full list of affected products and corresponding patches is available in the vendor security advisory [1]. No workaround is provided; patching is the only mitigation.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7
  • Range: Versions earlier than 10.1.0.160(C00E160R3P8)
  • Huawei/Huawei Paycpe-rescue
    Range: Versions earlier than 10.1.0.160(C00E160R2P11)
  • Huawei/HUAWEI P30cpe-rescue
    Range: Versions earlier than 10.1.0.160(C00E160R2P8)
  • Huawei/Princeton-AL10Dv5
    Range: Versions earlier than 10.1.0.160(C00E160R2P11)
  • Huawei/Yale-AL00Av5
    Range: Versions earlier than 10.1.0.160(C00E160R8P12)
  • Huawei/Yale-AL50Av5
    Range: Versions earlier than 10.1.0.88(C00E88R8P1)
  • Huawei/YaleP-AL10Bv5
    Range: Versions earlier than 10.1.0.160(C00E160R8P12)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.