Vendor CVEs
Huawei
All CVEs
2,386 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-2723 | Med | 0.44 | 6.7 | 0.00 | Nov 22, 2017 | The Files APP 7.1.1.308 and earlier versions in some Huawei mobile phones has a vulnerability of plaintext storage of users' Safe passwords. An attacker with the root privilege of an Android system could forge the Safe to read users' plaintext Safe passwords, leading to… | ||
| CVE-2017-2703 | Med | 0.44 | 6.8 | 0.00 | Nov 22, 2017 | Phone Finder in versions earlier before MHA-AL00BC00B156,Versions earlier before MHA-CL00BC00B156,Versions earlier before MHA-DL00BC00B156,Versions earlier before MHA-TL00BC00B156,Versions earlier before EVA-AL10C00B373,Versions earlier before EVA-CL10C00B373,Versions earlier… | ||
| CVE-2017-2702 | Med | 0.44 | 6.8 | 0.00 | Nov 22, 2017 | Phone Finder in versions earlier before MHA-AL00C00B170 can be bypass. An attacker can bypass the Phone Finder by special steps and obtain the owner of the phone. | ||
| CVE-2017-2691 | Med | 0.44 | 6.8 | 0.00 | Nov 22, 2017 | Huawei P9 versions earlier before EVA-AL10C00B373, versions earlier before EVA-CL00C92B373, versions earlier before EVA-DL00C17B373, versions earlier before EVA-TL00C01B373 have a lock-screen bypass vulnerability. An unauthenticated attacker could force the phone to the fastboot… | ||
| CVE-2015-6592 | Med | 0.44 | 6.8 | 0.00 | Sep 25, 2017 | Huawei UAP2105 before V300R012C00SPC160(BootRom) does not require authentication to the serial port or the VxWorks shell. | ||
| CVE-2016-8793 | Med | 0.44 | 6.7 | 0.00 | Apr 2, 2017 | Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368, Versions before… | ||
| CVE-2016-8775 | Med | 0.44 | 6.7 | 0.00 | Apr 2, 2017 | Touch Panel (TP) driver in Huawei NEM phones with software Versions before NEM-AL10C00B130, Versions before NEM-UL10C17B160, Versions before NEM-UL10C00B160, Versions before NEM-TL00C01B160 allows attackers to get root privilege or crash the system or execute arbitrary code,… | ||
| CVE-2016-8774 | Med | 0.44 | 6.7 | 0.00 | Apr 2, 2017 | The HIFI driver in Huawei Mate 8 phones with software versions before NXT-AL10C00B386, versions before NXT-CL00C92B386, versions before NXT-DL00C17B386, versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368,… | ||
| CVE-2015-8673 | Med | 0.44 | 6.8 | 0.00 | Jan 12, 2016 | Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 do not require entry of the old password when changing the password for the Debug account, which allows physically proximate attackers to change the password by… | ||
| CVE-2026-41976 | Med | 0.43 | 6.6 | 0.00 | Jun 9, 2026 | Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2026-28549 | Med | 0.43 | 6.6 | 0.00 | Mar 5, 2026 | Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58314 | Med | 0.43 | 6.6 | 0.00 | Nov 28, 2025 | Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2025-54644 | Med | 0.43 | 6.6 | 0.00 | Aug 6, 2025 | Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54643 | Med | 0.43 | 6.6 | 0.00 | Aug 6, 2025 | Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-53185 | Med | 0.43 | 6.6 | 0.00 | Jul 7, 2025 | Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory Impact: Successful exploitation of this vulnerability may affect service integrity. | ||
| CVE-2025-48902 | Med | 0.43 | 6.6 | 0.00 | Jun 6, 2025 | Vulnerability of uncontrolled system resource applications in the setting module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-57957 | Med | 0.43 | 6.6 | 0.00 | Feb 6, 2025 | Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-56449 | Med | 0.43 | 6.6 | 0.00 | Jan 8, 2025 | Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-51530 | Med | 0.43 | 6.6 | 0.00 | Nov 5, 2024 | LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-42034 | Med | 0.43 | 6.6 | 0.00 | Aug 8, 2024 | LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2020-1796 | Med | 0.43 | 6.6 | 0.00 | Mar 20, 2020 | There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do certain operation which the user are supposed not to do.Affected product… | ||
| CVE-2020-1787 | Med | 0.43 | 6.6 | 0.00 | Jan 9, 2020 | HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error under certain scenario, successful exploit could allow the attacker who gains the privilege of guest user to access to the host… | ||
| CVE-2016-6898 | Med | 0.43 | 6.6 | 0.01 | Sep 7, 2016 | XML external entity (XXE) vulnerability in the Hyper Management Module (HMM) in Huawei E9000 rack servers with software before V100R001C00SPC296 allows remote authenticated users to read arbitrary files or cause a denial of service (web service outage) via a crafted XML document. | ||
| CVE-2026-41982 | Med | 0.42 | 6.4 | 0.00 | Jun 9, 2026 | Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-28552 | Med | 0.42 | 6.5 | 0.00 | Mar 5, 2026 | Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-24917 | Med | 0.42 | 6.5 | 0.00 | Feb 6, 2026 | UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58307 | Med | 0.42 | 6.4 | 0.00 | Nov 28, 2025 | UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-53184 | Med | 0.42 | 6.5 | 0.00 | Jul 7, 2025 | Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2025-53183 | Med | 0.42 | 6.5 | 0.00 | Jul 7, 2025 | Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2025-53182 | Med | 0.42 | 6.5 | 0.00 | Jul 7, 2025 | Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2025-53181 | Med | 0.42 | 6.5 | 0.00 | Jul 7, 2025 | Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2025-53180 | Med | 0.42 | 6.5 | 0.00 | Jul 7, 2025 | Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2025-53179 | Med | 0.42 | 6.5 | 0.00 | Jul 7, 2025 | Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2023-52955 | Med | 0.42 | 6.5 | 0.00 | Jan 8, 2025 | Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2023-52718 | Med | 0.42 | 6.4 | 0.00 | Dec 28, 2024 | A connection hijacking vulnerability exists in some Huawei home routers. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-34408) This vulnerability has been assigned a (CVE)ID:CVE-2023-52718 | ||
| CVE-2020-9211 | Med | 0.42 | 6.4 | 0.00 | Dec 27, 2024 | There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by modifying some configuration to cause out-of-bound read and write, causing denial of service. (Vulnerability… | ||
| CVE-2024-54113 | Med | 0.42 | 6.5 | 0.00 | Dec 12, 2024 | Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect power consumption. | ||
| CVE-2024-54109 | Med | 0.42 | 6.5 | 0.00 | Dec 12, 2024 | Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-54108 | Med | 0.42 | 6.5 | 0.00 | Dec 12, 2024 | Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-4046 | Med | 0.42 | 6.4 | 0.00 | May 14, 2024 | Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52554 | Med | 0.42 | 6.5 | 0.00 | Apr 8, 2024 | Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2023-52542 | Med | 0.42 | 6.5 | 0.00 | Apr 8, 2024 | Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2022-48616 | Med | 0.42 | 6.4 | 0.01 | Dec 12, 2023 | A Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability may allow attackers to gain higher privileges. | ||
| CVE-2022-48469 | Med | 0.42 | 6.5 | 0.00 | Jun 16, 2023 | There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this vulnerability can cause packets to be hijacked by attackers. | ||
| CVE-2022-48314 | Med | 0.42 | 6.5 | 0.00 | Apr 16, 2023 | The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48313 | Med | 0.42 | 6.5 | 0.00 | Apr 16, 2023 | The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48355 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2023 | The Bluetooth module has a heap out-of-bounds read vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash. | ||
| CVE-2022-48354 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2023 | The Bluetooth module has a heap out-of-bounds write vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash. | ||
| CVE-2022-48291 | Med | 0.42 | 6.5 | 0.00 | Mar 27, 2023 | The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2022-48293 | Med | 0.42 | 6.5 | 0.00 | Feb 9, 2023 | The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. |
- risk 0.44cvss 6.7epss 0.00
The Files APP 7.1.1.308 and earlier versions in some Huawei mobile phones has a vulnerability of plaintext storage of users' Safe passwords. An attacker with the root privilege of an Android system could forge the Safe to read users' plaintext Safe passwords, leading to…
- risk 0.44cvss 6.8epss 0.00
Phone Finder in versions earlier before MHA-AL00BC00B156,Versions earlier before MHA-CL00BC00B156,Versions earlier before MHA-DL00BC00B156,Versions earlier before MHA-TL00BC00B156,Versions earlier before EVA-AL10C00B373,Versions earlier before EVA-CL10C00B373,Versions earlier…
- risk 0.44cvss 6.8epss 0.00
Phone Finder in versions earlier before MHA-AL00C00B170 can be bypass. An attacker can bypass the Phone Finder by special steps and obtain the owner of the phone.
- risk 0.44cvss 6.8epss 0.00
Huawei P9 versions earlier before EVA-AL10C00B373, versions earlier before EVA-CL00C92B373, versions earlier before EVA-DL00C17B373, versions earlier before EVA-TL00C01B373 have a lock-screen bypass vulnerability. An unauthenticated attacker could force the phone to the fastboot…
- risk 0.44cvss 6.8epss 0.00
Huawei UAP2105 before V300R012C00SPC160(BootRom) does not require authentication to the serial port or the VxWorks shell.
- risk 0.44cvss 6.7epss 0.00
Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368, Versions before…
- risk 0.44cvss 6.7epss 0.00
Touch Panel (TP) driver in Huawei NEM phones with software Versions before NEM-AL10C00B130, Versions before NEM-UL10C17B160, Versions before NEM-UL10C00B160, Versions before NEM-TL00C01B160 allows attackers to get root privilege or crash the system or execute arbitrary code,…
- risk 0.44cvss 6.7epss 0.00
The HIFI driver in Huawei Mate 8 phones with software versions before NXT-AL10C00B386, versions before NXT-CL00C92B386, versions before NXT-DL00C17B386, versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92B368,…
- risk 0.44cvss 6.8epss 0.00
Huawei TE30, TE40, TE50, and TE60 multimedia video conferencing endpoints with software before V100R001C10SPC100 do not require entry of the old password when changing the password for the Debug account, which allows physically proximate attackers to change the password by…
- risk 0.43cvss 6.6epss 0.00
Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.43cvss 6.6epss 0.00
Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.43cvss 6.6epss 0.00
Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.43cvss 6.6epss 0.00
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.43cvss 6.6epss 0.00
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.43cvss 6.6epss 0.00
Virtual address reuse issue in the memory management module, which can be exploited by non-privileged users to access released memory Impact: Successful exploitation of this vulnerability may affect service integrity.
- risk 0.43cvss 6.6epss 0.00
Vulnerability of uncontrolled system resource applications in the setting module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.43cvss 6.6epss 0.00
Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.43cvss 6.6epss 0.00
Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.43cvss 6.6epss 0.00
LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.43cvss 6.6epss 0.00
LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.43cvss 6.6epss 0.00
There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do certain operation which the user are supposed not to do.Affected product…
- risk 0.43cvss 6.6epss 0.00
HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error under certain scenario, successful exploit could allow the attacker who gains the privilege of guest user to access to the host…
- risk 0.43cvss 6.6epss 0.01
XML external entity (XXE) vulnerability in the Hyper Management Module (HMM) in Huawei E9000 rack servers with software before V100R001C00SPC296 allows remote authenticated users to read arbitrary files or cause a denial of service (web service outage) via a crafted XML document.
- risk 0.42cvss 6.4epss 0.00
Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.42cvss 6.5epss 0.00
Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.42cvss 6.5epss 0.00
UAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.42cvss 6.4epss 0.00
UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.42cvss 6.5epss 0.00
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.42cvss 6.5epss 0.00
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.42cvss 6.5epss 0.00
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.42cvss 6.5epss 0.00
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.42cvss 6.5epss 0.00
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.42cvss 6.5epss 0.00
Null pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.42cvss 6.5epss 0.00
Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.42cvss 6.4epss 0.00
A connection hijacking vulnerability exists in some Huawei home routers. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-34408) This vulnerability has been assigned a (CVE)ID:CVE-2023-52718
- risk 0.42cvss 6.4epss 0.00
There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by modifying some configuration to cause out-of-bound read and write, causing denial of service. (Vulnerability…
- risk 0.42cvss 6.5epss 0.00
Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect power consumption.
- risk 0.42cvss 6.5epss 0.00
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.42cvss 6.5epss 0.00
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.42cvss 6.4epss 0.00
Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.42cvss 6.5epss 0.00
Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.42cvss 6.5epss 0.00
Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.42cvss 6.4epss 0.01
A Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability may allow attackers to gain higher privileges.
- risk 0.42cvss 6.5epss 0.00
There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this vulnerability can cause packets to be hijacked by attackers.
- risk 0.42cvss 6.5epss 0.00
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.42cvss 6.5epss 0.00
The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.42cvss 6.5epss 0.00
The Bluetooth module has a heap out-of-bounds read vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash.
- risk 0.42cvss 6.5epss 0.00
The Bluetooth module has a heap out-of-bounds write vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash.
- risk 0.42cvss 6.5epss 0.00
The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.42cvss 6.5epss 0.00
The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
Page 27 of 48