VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2019-5248HigDec 13, 2019
    risk 0.48cvss 7.4epss 0.00

    CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets. As a result, a memory leak occurs after the device uses the specific packet. As a result, the attacker can exploit this vulnerability to cause DoS attacks on…

  • CVE-2018-7960HigNov 27, 2018
    risk 0.48cvss 7.4epss 0.01

    There is a SRTP icon display vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept the packets in non-secure transmission mode. Successful exploitation may intercept and tamper with the call information,…

  • CVE-2018-7958HigNov 27, 2018
    risk 0.48cvss 7.4epss 0.01

    There is an anonymous TLS cipher suites supported vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to hijack the connection from a client when the user signs up to log in by TLS. Due to insufficient authentication,…

  • CVE-2016-6192HigAug 2, 2016
    risk 0.48cvss 7.3epss 0.01

    Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6193.

  • CVE-2016-5722HigJun 24, 2016
    risk 0.48cvss 7.3epss 0.01

    Huawei OceanStor 5300 V3, 5500 V3, 5600 V3, 5800 V3, 6800 V3, 18800 V3, and 18500 V3 before V300R003C10 sends the plaintext session token in the HTTP header, which allows remote attackers to conduct replay attacks and obtain sensitive information by sniffing the network.

  • CVE-2015-8331HigJan 11, 2016
    risk 0.48cvss 7.4epss 0.01

    The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 does not properly invalidate the session ID when an "abnormal exit" occurs, which allows remote attackers to conduct replay attacks via the session ID.

  • CVE-2026-34856HigApr 13, 2026
    risk 0.47cvss 7.3epss 0.00

    UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-28542HigMar 5, 2026
    risk 0.47cvss 7.3epss 0.00

    Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-24925HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58308HigNov 28, 2025
    risk 0.47cvss 7.3epss 0.00

    Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2025-58316HigNov 28, 2025
    risk 0.47cvss 7.3epss 0.00

    DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58298HigOct 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54611HigAug 6, 2025
    risk 0.47cvss 7.3epss 0.00

    EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54606HigAug 6, 2025
    risk 0.47cvss 7.3epss 0.00

    Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2024-58043HigMar 4, 2025
    risk 0.47cvss 7.3epss 0.00

    Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-56451HigJan 8, 2025
    risk 0.47cvss 7.3epss 0.00

    Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-7263HigDec 28, 2024
    risk 0.47cvss 7.3epss 0.00

    Some Huawei home music system products have a path traversal vulnerability. Successful exploitation of this vulnerability may cause unauthorized file deletion or file permission change.(Vulnerability ID:HWPSIRT-2023-53450) This vulnerability has been assigned a…

  • CVE-2024-54097HigDec 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.

  • CVE-2024-36503HigJun 14, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-48681HigMay 28, 2024
    risk 0.47cvss 7.2epss 0.00

    Some Huawei smart speakers have a memory overflow vulnerability. Successful exploitation of this vulnerability may cause certain functions to fail.

  • CVE-2021-37127HigOct 27, 2021
    risk 0.47cvss 7.2epss 0.01

    There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmware update process, successful exploit this vulnerability can cause the forged system file overwrite the correct system file.…

  • CVE-2021-37106HigSep 28, 2021
    risk 0.47cvss 7.2epss 0.01

    There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently…

  • CVE-2021-22377HigJun 22, 2021
    risk 0.47cvss 7.2epss 0.01

    There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by…

  • CVE-2021-22311HigMar 22, 2021
    risk 0.47cvss 7.2epss 0.01

    There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening, the process can run with a higher privilege. Successful exploit could allow certain users to do certain operations with improper permissions. Affected…

  • CVE-2020-9116HigDec 1, 2020
    risk 0.47cvss 7.2epss 0.01

    Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. Due to insufficient verification, this could be exploited to cause the attackers to obtain higher…

  • CVE-2020-9115HigDec 1, 2020
    risk 0.47cvss 7.2epss 0.01

    ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the plug-in component. Due to insufficient…

  • CVE-2017-17172HigJun 14, 2018
    risk 0.47cvss 7.3epss 0.00

    Huawei smart phones LYO-L21 with software LYO-L21C479B107, LYO-L21C479B107 have a privilege escalation vulnerability. An authenticated, local attacker can crafts malformed packets after tricking a user to install a malicious application and exploit this vulnerability when in the…

  • CVE-2017-8187HigMar 20, 2018
    risk 0.47cvss 7.2epss 0.01

    Huawei FusionSphere OpenStack V100R006C00SPC102(NFV) has a privilege escalation vulnerability. Due to improper privilege restrictions, an attacker with high privilege may obtain the other users' certificates. Successful exploit may cause privilege escalation.

  • CVE-2017-8198HigNov 22, 2017
    risk 0.47cvss 7.2epss 0.01

    FusionSphere V100R006C00SPC102(NFV) has an SQL injection vulnerability. An authenticated, remote attacker could craft interface messages carrying malicious SQL statements and send them to a target device. Successful exploit could allow the attacker to launch an SQL injection…

  • CVE-2017-8197HigNov 22, 2017
    risk 0.47cvss 7.2epss 0.02

    FusionSphere V100R006C00SPC102(NFV) has a command injection vulnerability. An authenticated, remote attacker could craft packets with malicious strings and send them to a target device. Successful exploit could allow the attacker to launch a command injection attack and execute…

  • CVE-2017-8188HigNov 22, 2017
    risk 0.47cvss 7.2epss 0.02

    FusionSphere OpenStack V100R006C00SPC102(NFV)has a command injection vulnerability. Due to lack of validation, an attacker with high privilege may inject malicious code into some module of the affected products, causing code execution.

  • CVE-2017-2736HigNov 22, 2017
    risk 0.47cvss 7.2epss 0.01

    VCM5010 with software versions earlier before V100R002C50SPC100 has a command injection vulnerability. This is due to insufficient validation of user's input. An authenticated attacker could launch a command injection attack.

  • CVE-2016-8801HigApr 2, 2017
    risk 0.47cvss 7.2epss 0.01

    Huawei OceanStor 5600 V3 with V300R003C00C10 and earlier versions allows attackers with administrator privilege to inject a command into a specific command's parameters, and run this injected command with root privilege.

  • CVE-2016-8769MedApr 2, 2017
    risk 0.47cvss 6.7epss 0.02

    Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after…

  • CVE-2026-28548HigMar 5, 2026
    risk 0.46cvss 7.1epss 0.00

    Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-66327HigDec 8, 2025
    risk 0.46cvss 7.1epss 0.00

    Race condition vulnerability in the network module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-48909HigJun 6, 2025
    risk 0.46cvss 7.1epss 0.00

    Bypass vulnerability in the device management channel Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2020-9222HigDec 27, 2024
    risk 0.46cvss 7.0epss 0.00

    There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can exploit this vulnerability to elevate permissions. (Vulnerability ID: HWPSIRT-2020-05241) This…

  • CVE-2024-54107HigDec 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-54106HigDec 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-51523HigNov 5, 2024
    risk 0.46cvss 7.1epss 0.00

    Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52719HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.00

    Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2022-41577HigOct 14, 2022
    risk 0.46cvss 7.1epss 0.00

    The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability.

  • CVE-2021-22437HigFeb 25, 2022
    risk 0.46cvss 7.0epss 0.00

    There is a software integer overflow leading to a TOCTOU condition in smartphones. Successful exploitation of this vulnerability may cause random address access.

  • CVE-2021-22469HigOct 28, 2021
    risk 0.46cvss 7.1epss 0.00

    A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause kernel out-of-bounds read.

  • CVE-2021-22386HigAug 10, 2021
    risk 0.46cvss 7.0epss 0.00

    A component of the Huawei smartphone has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevation of Privileges.

  • CVE-2021-22326HigJun 30, 2021
    risk 0.46cvss 7.1epss 0.00

    A component of the HarmonyOS has a Privilege Dropping / Lowering Errors vulnerability. Local attackers may exploit this vulnerability to obtain Kernel space read/write capability.

  • CVE-2021-22302HigFeb 6, 2021
    risk 0.46cvss 7.1epss 0.00

    There is an out-of-bound read vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module does not verify the some input. Attackers can exploit this vulnerability by sending malicious input through specific app. This could cause out-of-bound, compromising normal service.

  • CVE-2020-9241HigAug 17, 2020
    risk 0.46cvss 7.0epss 0.00

    Huawei 5G Mobile WiFi E6878-370 with versions of 10.0.3.1(H563SP1C00),10.0.3.1(H563SP21C233) have an improper authorization vulnerability. The device does not restrict certain data received from WAN port. Successful exploit could allow an attacker at WAN side to manage certain…

  • CVE-2020-1808HigMay 15, 2020
    risk 0.46cvss 7.1epss 0.01

    Honor 20;HONOR 20 PRO;Honor Magic2;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;Honor View 20 smartphones with versions earlier than 10.0.0.187(C00E60R4P11); versions earlier than 10.0.0.187(C00E60R4P11); versions earlier than 10.0.0.176(C00E60R2P11);9.1.0.135(C00E133R2P1);…

Page 24 of 48