VYPR
Unrated severityNVD Advisory· Published Oct 28, 2021· Updated Aug 4, 2024

CVE-2021-36991

CVE-2021-36991

Description

There is an Unauthorized file access vulnerability in Huawei Smartphone due to unstandardized path input.Successful exploitation of this vulnerability by creating malicious file paths can cause unauthorized file access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2021-36991 allows unauthorized file access on Huawei Smartphones due to unstandardized path input, enabling malicious file paths.

Vulnerability

CVE-2021-36991 is an unauthorized file access vulnerability in Huawei Smartphones, caused by unstandardized path input handling. The affected software includes EMUI 11.0.0, EMUI 10.1.1, Magic UI 4.0.0, and Magic UI 3.1.1 (as referenced in the July 2021 security bulletin) [1]. Successful exploitation requires an attacker to create malicious file paths to bypass intended access controls.

Exploitation

An attacker with local access to the device can exploit the vulnerability by crafting malicious file paths that are not properly sanitized. No authentication or user interaction is required beyond the ability to create files or influence file path inputs on the system. The unstandardized path input allows traversal or access to files outside the intended directory scope [1].

Impact

Successful exploitation leads to unauthorized file access, potentially allowing the attacker to read sensitive files stored on the device. The impact primarily affects confidentiality, as the attacker can access files they are not normally permitted to view. The vulnerability does not directly enable code execution or privilege escalation beyond the file access scope [1].

Mitigation

Huawei released a fix in its July 2021 security update. Users should update their devices to the latest software version that includes the patch for CVE-2021-36991. The update is available through Huawei's official security bulletin [1]. No known workarounds are documented; applying the security update is the recommended mitigation.

References
  1. July

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.