VYPR
Unrated severityNVD Advisory· Published Jul 17, 2020· Updated Aug 4, 2024

CVE-2020-9254

CVE-2020-9254

Description

HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a logic check error vulnerability. A logic error occurs when the software checking the size of certain parameter, the attacker should trick the user into installing a malicious application, successful exploit may cause code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Logic check error in Huawei P30 Pro through malicious app leads to code execution; fixed in firmware updates.

Vulnerability

CVE-2020-9254 is a logic check error vulnerability in Huawei P30 Pro smartphones. The flaw exists when the software checks the size of a certain parameter, leading to a logic error. Affected versions include those earlier than 10.1.0.123(C432E19R2P5patch02), 10.1.0.126(C10E11R5P1), and 10.1.0.160(C00E160R2P8) [1].

Exploitation

Exploitation requires an attacker to trick the user into installing a malicious application. The app then exploits the logic check error to achieve code execution. No additional privileges or network access are needed beyond user interaction [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code on the device, potentially gaining full control over the affected smartphone [1].

Mitigation

Huawei has released software updates to fix this vulnerability. Users should update their devices to version 10.1.0.123(C432E19R2P5patch02), 10.1.0.126(C10E11R5P1), or 10.1.0.160(C00E160R2P8) as applicable [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Huawei/P30 Prollm-fuzzy
    Range: <10.1.0.123(C432E19R2P5patch02), <10.1.0.126(C10E11R5P1), <10.1.0.160(C00E160R2P8)
  • Huawei/HUAWEI P30cpe-rescue
    Range: Versions earlier than 10.1.0.123(C432E19R2P5patch02)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.