VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2019-5293MedNov 13, 2019
    risk 0.42cvss 6.5epss 0.01

    Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation privilege could exploit the vulnerability by sending specific messages continuously. Successful exploit may cause some service to be abnormal.

  • CVE-2019-5280MedAug 13, 2019
    risk 0.42cvss 6.5epss 0.00

    The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due to insufficient verification of specific parameters of the TLS server certificate, attackers can perform man-in-the-middle attacks, leading to the affected…

  • CVE-2019-5221MedJul 10, 2019
    risk 0.42cvss 6.5epss 0.00

    There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker could crafted a file path when transporting file through Huawei Share, successful exploit could allow the attacker to transport a file to arbitrary path on the…

  • CVE-2019-5295MedJun 6, 2019
    risk 0.42cvss 6.4epss 0.00

    Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8) have an authorization bypass vulnerability. Due to improper authorization implementation logic, attackers can bypass certain authorization scopes of smart phones by performing specific…

  • CVE-2019-5284MedJun 4, 2019
    risk 0.42cvss 6.5epss 0.01

    There is a DoS vulnerability in RTSP module of Leland-AL00A Huawei smart phones versions earlier than Leland-AL00A 9.1.0.111(C00E111R2P10T8). Remote attackers could trick the user into opening a malformed RTSP media stream to exploit this vulnerability. Successful exploit could…

  • CVE-2018-7900MedJan 2, 2019
    risk 0.42cvss 6.5epss 0.01

    There is an information leak vulnerability in some Huawei HG products. An attacker may obtain information about the HG device by exploiting this vulnerability.

  • CVE-2018-7961MedNov 27, 2018
    risk 0.42cvss 6.5epss 0.01

    There is a smart SMS verification code vulnerability in some Huawei smart phones. An attacker should trick a user to access malicious Website or malicious App and register. Due to incorrect processing of the smart SMS verification code, successful exploitation can cause…

  • CVE-2017-17175MedJul 2, 2018
    risk 0.42cvss 6.5epss 0.00

    Short Message Service (SMS) module of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.354(C00) has a Denial of Service (DoS) vulnerability. An unauthenticated attacker may set up a pseudo base station, and send special malware text message to the phone,…

  • CVE-2017-17318MedApr 30, 2018
    risk 0.42cvss 6.5epss 0.00

    Huawei MBB (Mobile Broadband) products E5771h-937 with the versions before E5771h-937TCPU-V200R001B328D62SP00C1133 and the versions before E5771h-937TCPU-V200R001B329D05SP00C1308 have a Denial of Service (DoS) vulnerability. When an attacker accessing device sends special http…

  • CVE-2017-15315MedMar 9, 2018
    risk 0.42cvss 6.5epss 0.01

    Patch module of Huawei NIP6300 V500R001C20SPC100, V500R001C20SPC200, NIP6600 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6300 V500R001C20SPC100, V500R001C20SPC200, Secospace USG6500 V500R001C20SPC100, V500R001C20SPC200 has a memory leak vulnerability. An authenticated…

  • CVE-2017-17304MedMar 9, 2018
    risk 0.42cvss 6.5epss 0.01

    The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented. An authenticated remote attacker could send a malicious message to a target system. Successful exploit…

  • CVE-2017-17250MedMar 9, 2018
    risk 0.42cvss 6.5epss 0.01

    Huawei AR120-S V200R005C32; AR1200 V200R005C32; AR1200-S V200R005C32; AR150 V200R005C32; AR150-S V200R005C32; AR160 V200R005C32; AR200 V200R005C32; AR200-S V200R005C32; AR2200-S V200R005C32; AR3200 V200R005C32; V200R007C00; AR510 V200R005C32; NetEngine16EX V200R005C32; SRG1300…

  • CVE-2017-17170MedMar 9, 2018
    risk 0.42cvss 6.5epss 0.01

    The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented. An authenticated remote attacker could send a malicious message to a target system. Successful exploit…

  • CVE-2017-17169MedMar 9, 2018
    risk 0.42cvss 6.5epss 0.01

    The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented. An authenticated remote attacker could send a malicious message to a target system. Successful exploit…

  • CVE-2017-17168MedMar 9, 2018
    risk 0.42cvss 6.5epss 0.01

    The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the protocol is implemented. An authenticated remote attacker could send a malicious message to a target system. Successful exploit…

  • CVE-2017-17159MedFeb 15, 2018
    risk 0.42cvss 6.5epss 0.00

    Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL00C00B535 have a DoS vulnerability due to insufficient input validation. An unauthenticated attacker could send malformed System Information(SI) messages to…

  • CVE-2017-15322MedDec 22, 2017
    risk 0.42cvss 6.5epss 0.00

    Some Huawei smartphones with software of BGO-L03C158B003CUSTC158D001 and BGO-L03C331B009CUSTC331D001 have a DoS vulnerability due to insufficient input validation. An attacker could exploit this vulnerability by sending specially crafted NFC messages to the target device.…

  • CVE-2017-15310MedDec 22, 2017
    risk 0.42cvss 6.5epss 0.01

    Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploit this vulnerability to delete specific files from the SD card.

  • CVE-2017-8201MedNov 22, 2017
    risk 0.42cvss 6.5epss 0.01

    MAX PRESENCE V100R001C00, TP3106 V100R002C00, TP3206 V100R002C00 have an a memory leak vulnerability in H323 protocol. An attacker logs in to the system as a user and send crafted packets to the affected products. Due to insufficient verification of the packets, successful…

  • CVE-2017-8200MedNov 22, 2017
    risk 0.42cvss 6.5epss 0.01

    MAX PRESENCE V100R001C00, TP3106 V100R002C00, TP3206 V100R002C00 have an out-of-bounds read vulnerability in H323 protocol. An attacker logs in to the system as a user and send crafted packets to the affected products. Due to insufficient verification of the packets, successful…

  • CVE-2017-8199MedNov 22, 2017
    risk 0.42cvss 6.5epss 0.01

    MAX PRESENCE V100R001C00, TP3106 V100R002C00, TP3206 V100R002C00 have an out-of-bounds read vulnerability in H323 protocol. An attacker logs in to the system as a user and send crafted packets to the affected products. Due to insufficient verification of the packets, successful…

  • CVE-2017-8163MedNov 22, 2017
    risk 0.42cvss 6.5epss 0.01

    AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR1200-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR150 with software…

  • CVE-2017-8162MedNov 22, 2017
    risk 0.42cvss 6.5epss 0.01

    AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR1200-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR150 with software…

  • CVE-2017-8158MedNov 22, 2017
    risk 0.42cvss 6.5epss 0.00

    FusionCompute V100R005C00 and V100R005C10 have an improper authorization vulnerability due to improper permission settings for a certain file on the host machine. An authenticated attacker could create a large number of virtual machine (VM) processes to exhaust system resources.…

  • CVE-2017-8130MedNov 22, 2017
    risk 0.42cvss 6.5epss 0.01

    The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.

  • CVE-2017-2728MedNov 22, 2017
    risk 0.42cvss 6.4epss 0.00

    Some Huawei mobile phones Honor 6X Berlin-L22C636B150 and earlier versions have a Bluetooth unlock bypassing vulnerability. If a user has enabled the smart unlock function, an attacker can impersonate the user's Bluetooth device to unlock the user's mobile phone screen.uawei…

  • CVE-2017-2717MedNov 22, 2017
    risk 0.42cvss 6.5epss 0.00

    honor 8 Pro with software Duke-L09C10B120 and earlier versions,Duke-L09C432B120 and earlier versions,Duke-L09C636B120 and earlier versions has an integer overflow vulnerability. The attacker sends a response message to the device, which contains an illegal length field, it could…

  • CVE-2016-8802MedApr 2, 2017
    risk 0.42cvss 6.5epss 0.01

    The security policy processing module in Huawei Secospace USG6300 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6500 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6600 with software V500R001C20SPC100,…

  • CVE-2016-8781MedApr 2, 2017
    risk 0.42cvss 6.5epss 0.01

    Huawei Secospace USG6300 with software V500R001C20 and V500R001C20SPC200PWE, Secospace USG6500 with software V500R001C20, Secospace USG6600 with software V500R001C20 and V500R001C20SPC200PWE allow remote attackers with specific permission to log in to a device and deliver a…

  • CVE-2016-8780MedApr 2, 2017
    risk 0.42cvss 6.5epss 0.01

    Huawei CloudEngine 6800 V100R006C00, CloudEngine 7800 V100R006C00, CloudEngine 8800 V100R006C00, and CloudEngine 12800 V100R006C00 allow remote attackers with specific permission to store massive files to exhaust the shared storage space, leading to a DoS condition.

  • CVE-2016-8779MedApr 2, 2017
    risk 0.42cvss 6.5epss 0.01

    Huawei FusionAccess with software V100R005C10 and V100R005C20 could allow remote attackers with specific permission to inject a Lightweight Directory Access Protocol (LDAP) operation command into a specific input variable to obtain sensitive information from the database.

  • CVE-2016-8764MedApr 2, 2017
    risk 0.42cvss 6.4epss 0.00

    The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an input validation vulnerability, which allows…

  • CVE-2016-8275MedApr 2, 2017
    risk 0.42cvss 6.5epss 0.01

    Huawei AnyOffice V200R006C00 could allow an authenticated, remote attacker to cause the software to deny services by uploading an XML bomb.

  • CVE-2016-6177MedApr 2, 2017
    risk 0.42cvss 6.5epss 0.01

    The Huawei OceanStor 5800 V300R003C00 has an integer overflow vulnerability. An authenticated attacker may send massive abnormal Network File System (NFS) packets, causing an anomaly in specific disk arrays.

  • CVE-2015-8670MedApr 2, 2017
    risk 0.42cvss 6.5epss 0.01

    Huawei LogCenter V100R001C10 could allow an authenticated attacker to add abnormal device information to the log collection module, causing denial of service.

  • CVE-2014-9691MedApr 2, 2017
    risk 0.42cvss 6.5epss 0.01

    Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 and earlier versions, Tecal RH2268 V2 V100R002C00, Tecal RH2288 V2…

  • CVE-2016-8280MedOct 3, 2016
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in Huawei eSight before V300R003C20SPC005 allows remote authenticated users to read arbitrary files via unspecified vectors.

  • CVE-2016-8277MedOct 3, 2016
    risk 0.42cvss 6.5epss 0.01

    Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote authenticated users to cause a denial of service (device restart) via an unspecified command parameter.

  • CVE-2016-6901MedSep 26, 2016
    risk 0.42cvss 6.5epss 0.01

    Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR3600 routers with software before V200R007C00SPC900 and NetEngine 16EX routers with software before V200R007C00SPC900 allows remote authenticated users to cause…

  • CVE-2016-6827MedSep 26, 2016
    risk 0.42cvss 6.5epss 0.01

    Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

  • CVE-2016-6826MedSep 26, 2016
    risk 0.42cvss 6.5epss 0.01

    Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a crafted compressed email attachment.

  • CVE-2016-6824MedSep 22, 2016
    risk 0.42cvss 6.5epss 0.01

    Huawei AC6003, AC6005, AC6605, and ACU2 access controllers with software before V200R006C10SPC200 allows remote authenticated users to cause a denial of service (device restart) via crafted CAPWAP packets.

  • CVE-2016-7108MedSep 7, 2016
    risk 0.42cvss 6.5epss 0.01

    Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote authenticated users to obtain the MD5 hashes of arbitrary user passwords via unspecified vectors.

  • CVE-2016-4057MedJun 30, 2016
    risk 0.42cvss 6.5epss 0.01

    Huawei FusionCompute before V100R005C10SPC700 allows remote authenticated users to cause a denial of service (resource consumption) via a large number of crafted packets.

  • CVE-2016-3677MedJun 13, 2016
    risk 0.42cvss 6.5epss 0.00

    The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.

  • CVE-2016-3950MedApr 18, 2016
    risk 0.42cvss 6.5epss 0.01

    Huawei AR3200 routers with software before V200R006C10SPC300 allow remote authenticated users to cause a denial of service (restart) via crafted packets.

  • CVE-2015-8677MedApr 14, 2016
    risk 0.42cvss 6.5epss 0.01

    Memory leak in Huawei S5300EI, S5300SI, S5310HI, and S6300EI Campus series switches with software V200R003C00 before V200R003SPH011 and V200R005C00 before V200R005SPH008; S2350EI and S5300LI Campus series switches with software V200R003C00 before V200R003SPH011, V200R005C00…

  • CVE-2016-3676MedApr 11, 2016
    risk 0.42cvss 6.4epss 0.00

    Huawei E3276s USB modems with software before E3276s-150TCPU-V200R002B436D09SP00C00 allow man-in-the-middle attackers to intercept, spoof, or modify network traffic via unspecified vectors related to a fake network.

  • CVE-2015-8335MedJan 11, 2016
    risk 0.42cvss 6.5epss 0.01

    Huawei VCN500 with software before V100R002C00SPC201 logs passwords in cleartext, which allows remote authenticated users to obtain sensitive information by triggering log generation and then reading the log.

  • CVE-2026-41975MedJun 9, 2026
    risk 0.41cvss 6.3epss 0.00

    Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

Page 29 of 48