CVE-2021-36991
Description
There is an Unauthorized file access vulnerability in Huawei Smartphone due to unstandardized path input.Successful exploitation of this vulnerability by creating malicious file paths can cause unauthorized file access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CVE-2021-36991 allows unauthorized file access on Huawei Smartphones due to unstandardized path input, enabling malicious file paths.
Vulnerability
CVE-2021-36991 is an unauthorized file access vulnerability in Huawei Smartphones, caused by unstandardized path input handling. The affected software includes EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, and Magic UI 3.1.1 (as referenced in the July 2021 security bulletin) [1]. Successful exploitation requires an attacker to create malicious file paths to bypass intended access controls.
Exploitation
An attacker with local access to the device can exploit the vulnerability by crafting malicious file paths that are not properly sanitized. No authentication or user interaction is required beyond the ability to create files or influence file path inputs on the system. The unstandardized path input allows traversal or access to files outside the intended directory scope [1].
Impact
Successful exploitation leads to unauthorized file access, potentially allowing the attacker to read sensitive files stored on the device. The impact primarily affects confidentiality, as the attacker can access files they are not normally permitted to view. The vulnerability does not directly enable code execution or privilege escalation beyond the file access scope [1].
Mitigation
Huawei released a fix in its July 2021 security update. Users should update their devices to the latest software version that includes the patch for CVE-2021-36991. The update is available through Huawei's official security bulletin [1]. No known workarounds are documented; applying the security update is the recommended mitigation.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Huawei/Magic UIv5Range: 4.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- consumer.huawei.com/en/support/bulletin/2021/7/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.