Vendor CVEs
Huawei
All CVEs
2,386 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-56435 | Med | 0.40 | 6.2 | 0.00 | Jan 8, 2025 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-54122 | Med | 0.40 | 6.2 | 0.00 | Dec 12, 2024 | Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-54119 | Med | 0.40 | 6.2 | 0.00 | Dec 12, 2024 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-54117 | Med | 0.40 | 6.2 | 0.00 | Dec 12, 2024 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-54110 | Med | 0.40 | 6.2 | 0.00 | Dec 12, 2024 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-54104 | Med | 0.40 | 6.2 | 0.00 | Dec 12, 2024 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-54103 | Med | 0.40 | 6.1 | 0.00 | Dec 12, 2024 | Vulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-54102 | Med | 0.40 | 6.1 | 0.00 | Dec 12, 2024 | Race condition vulnerability in the DDR module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-54101 | Med | 0.40 | 6.2 | 0.00 | Dec 12, 2024 | Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-54100 | Med | 0.40 | 6.2 | 0.00 | Dec 12, 2024 | Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2024-51525 | Med | 0.40 | 6.2 | 0.00 | Nov 5, 2024 | Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-51522 | Med | 0.40 | 6.2 | 0.00 | Nov 5, 2024 | Vulnerability of improper device information processing in the device management module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-51516 | Med | 0.40 | 6.2 | 0.00 | Nov 5, 2024 | Permission control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to function abnormally. | ||
| CVE-2024-51515 | Med | 0.40 | 6.2 | 0.00 | Nov 5, 2024 | Race condition vulnerability in the kernel network module Impact:Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-51512 | Med | 0.40 | 6.2 | 0.00 | Nov 5, 2024 | Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-51511 | Med | 0.40 | 6.2 | 0.00 | Nov 5, 2024 | Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-47292 | Med | 0.40 | 6.2 | 0.00 | Sep 27, 2024 | Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-8298 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-45443 | Med | 0.40 | 6.1 | 0.01 | Sep 4, 2024 | Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2024-45441 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-42030 | Med | 0.40 | 6.2 | 0.00 | Aug 8, 2024 | Access permission verification vulnerability in the content sharing pop-up module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-39674 | Med | 0.40 | 6.2 | 0.00 | Jul 25, 2024 | Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-39670 | Med | 0.40 | 6.2 | 0.00 | Jul 25, 2024 | Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-32996 | Med | 0.40 | 6.2 | 0.00 | May 14, 2024 | Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-32995 | Med | 0.40 | 6.2 | 0.00 | May 14, 2024 | Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-32990 | Med | 0.40 | 6.1 | 0.00 | May 14, 2024 | Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52721 | Med | 0.40 | 6.2 | 0.00 | May 14, 2024 | The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality. | ||
| CVE-2023-52385 | Med | 0.40 | 6.2 | 0.00 | Apr 8, 2024 | Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52543 | Med | 0.40 | 6.2 | 0.00 | Apr 8, 2024 | Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52358 | Med | 0.40 | 6.2 | 0.00 | Feb 18, 2024 | Vulnerability of configuration defects in some APIs of the audio module.Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2020-36602 | Med | 0.40 | 6.1 | 0.00 | Sep 20, 2022 | There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message,… | ||
| CVE-2020-9119 | Med | 0.40 | 6.2 | 0.00 | Dec 24, 2020 | There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to physically contact the mobile phone and obtain higher privileges, and execute relevant commands, resulting in the user's privilege promotion. | ||
| CVE-2020-1855 | Med | 0.40 | 6.1 | 0.00 | Feb 18, 2020 | Huawei HEGE-570 version 1.0.1.22(SP3); and HEGE-560, OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X version 1.0.1.21(SP3) have an insufficient verification vulnerability. An attacker can access the device physically and exploit this vulnerability to tamper with device… | ||
| CVE-2019-5246 | Med | 0.40 | 6.2 | 0.00 | Nov 13, 2019 | Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability. The system does… | ||
| CVE-2019-5229 | Med | 0.40 | 6.2 | 0.00 | Nov 12, 2019 | P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high privilege to launch the attack,… | ||
| CVE-2019-5286 | Med | 0.40 | 6.1 | 0.01 | Jun 13, 2019 | There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS attacks. Affects HedEx Lite versions earlier than V200R006C00SPC007. | ||
| CVE-2018-7940 | Med | 0.40 | 6.2 | 0.00 | May 10, 2018 | Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high privilege obtains the smart phone and bypass the activation function by some… | ||
| CVE-2017-8215 | Med | 0.40 | 6.2 | 0.00 | Nov 22, 2017 | Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, versions earlier than FRD-DL00C00B391, versions earlier than KNT-AL10C00B391, versions earlier than KNT-AL20C00B391, versions… | ||
| CVE-2017-8214 | Med | 0.40 | 6.2 | 0.00 | Nov 22, 2017 | Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, versions earlier than FRD-DL00C00B391, versions earlier than KNT-AL10C00B391, versions earlier than KNT-AL20C00B391, versions… | ||
| CVE-2017-8182 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2017 | MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a out-of-bound read vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given… | ||
| CVE-2017-8139 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2017 | HedEx Earlier than V200R006C00 versions have the stored cross-site scripting (XSS) vulnerability. Attackers can exploit the vulnerability to plant malicious scripts into the configuration file to interrupt the services of legitimate users. | ||
| CVE-2017-8127 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2017 | The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks. | ||
| CVE-2017-8125 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2017 | The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks. | ||
| CVE-2016-8789 | Med | 0.40 | 6.1 | 0.01 | Apr 2, 2017 | Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicious scripts to obtain user information or hijack the session, aka XSS. | ||
| CVE-2016-6840 | Med | 0.40 | 6.1 | 0.01 | Sep 26, 2016 | Cross-site scripting (XSS) vulnerability in the management interface in Huawei OceanStor ISM before V200R001C04SPC200 allows remote attackers to inject arbitrary web script or HTML via the loginName parameter to cgi-bin/doLogin_CgiEntry and possibly other unspecified vectors. | ||
| CVE-2016-6158 | Med | 0.40 | 6.1 | 0.01 | Sep 21, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allow remote attackers to hijack the authentication of administrators for requests that (1) restore factory settings or (2) reboot the device via… | ||
| CVE-2016-6839 | Med | 0.40 | 6.1 | 0.01 | Sep 7, 2016 | CRLF injection vulnerability in Huawei FusionAccess before V100R006C00 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | ||
| CVE-2016-4575 | Med | 0.40 | 6.1 | 0.01 | May 25, 2016 | Cross-site scripting (XSS) vulnerability in the email APP in Huawei PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92 before AL10C92B211; ATH smartphones with software AL00C00 before AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361, and… | ||
| CVE-2015-8682 | Med | 0.40 | 6.1 | 0.01 | Apr 13, 2016 | The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B350, GRA-TL00 before GRA-TL00C01B350, GRA-CL00 before GRA-CL00C92B350, and GRA-CL10 before GRA-CL10C92B350 and Mate S smartphones with software CRR-TL00 before… | ||
| CVE-2016-2214 | Med | 0.40 | 6.1 | 0.01 | Feb 8, 2016 | Cross-site scripting (XSS) vulnerability in an unspecified portal authentication page in Huawei Agile Controller-Campus with software before V100R001C00SPC319 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. |
- risk 0.40cvss 6.2epss 0.00
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Concurrent variable access vulnerability in the ability module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.40cvss 6.2epss 0.00
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.1epss 0.00
Vulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.1epss 0.00
Race condition vulnerability in the DDR module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.40cvss 6.2epss 0.00
Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.40cvss 6.2epss 0.00
Permission control vulnerability in the clipboard module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Vulnerability of improper device information processing in the device management module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.40cvss 6.2epss 0.00
Permission control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to function abnormally.
- risk 0.40cvss 6.2epss 0.00
Race condition vulnerability in the kernel network module Impact:Successful exploitation of this vulnerability may affect availability.
- risk 0.40cvss 6.2epss 0.00
Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.40cvss 6.2epss 0.00
Vulnerability of parameter type not being verified in the WantAgent module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.40cvss 6.2epss 0.00
Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.1epss 0.01
Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.40cvss 6.2epss 0.00
Input verification vulnerability in the system service module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.40cvss 6.2epss 0.00
Access permission verification vulnerability in the content sharing pop-up module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.40cvss 6.2epss 0.00
Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.40cvss 6.2epss 0.00
Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.40cvss 6.2epss 0.00
Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.40cvss 6.2epss 0.00
Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.40cvss 6.1epss 0.00
Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.40cvss 6.2epss 0.00
The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality.
- risk 0.40cvss 6.2epss 0.00
Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.40cvss 6.2epss 0.00
Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.40cvss 6.2epss 0.00
Vulnerability of configuration defects in some APIs of the audio module.Successful exploitation of this vulnerability may affect availability.
- risk 0.40cvss 6.1epss 0.00
There is an out-of-bounds read and write vulnerability in some headset products. An unauthenticated attacker gets the device physically and crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message,…
- risk 0.40cvss 6.2epss 0.00
There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to physically contact the mobile phone and obtain higher privileges, and execute relevant commands, resulting in the user's privilege promotion.
- risk 0.40cvss 6.1epss 0.00
Huawei HEGE-570 version 1.0.1.22(SP3); and HEGE-560, OSCA-550, OSCA-550A, OSCA-550AX, and OSCA-550X version 1.0.1.21(SP3) have an insufficient verification vulnerability. An attacker can access the device physically and exploit this vulnerability to tamper with device…
- risk 0.40cvss 6.2epss 0.00
Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability. The system does…
- risk 0.40cvss 6.2epss 0.00
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high privilege to launch the attack,…
- risk 0.40cvss 6.1epss 0.01
There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS attacks. Affects HedEx Lite versions earlier than V200R006C00SPC007.
- risk 0.40cvss 6.2epss 0.00
Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high privilege obtains the smart phone and bypass the activation function by some…
- risk 0.40cvss 6.2epss 0.00
Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, versions earlier than FRD-DL00C00B391, versions earlier than KNT-AL10C00B391, versions earlier than KNT-AL20C00B391, versions…
- risk 0.40cvss 6.2epss 0.00
Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, versions earlier than FRD-DL00C00B391, versions earlier than KNT-AL10C00B391, versions earlier than KNT-AL20C00B391, versions…
- risk 0.40cvss 6.1epss 0.01
MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a out-of-bound read vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given…
- risk 0.40cvss 6.1epss 0.01
HedEx Earlier than V200R006C00 versions have the stored cross-site scripting (XSS) vulnerability. Attackers can exploit the vulnerability to plant malicious scripts into the configuration file to interrupt the services of legitimate users.
- risk 0.40cvss 6.1epss 0.01
The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.
- risk 0.40cvss 6.1epss 0.01
The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.
- risk 0.40cvss 6.1epss 0.01
Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicious scripts to obtain user information or hijack the session, aka XSS.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the management interface in Huawei OceanStor ISM before V200R001C04SPC200 allows remote attackers to inject arbitrary web script or HTML via the loginName parameter to cgi-bin/doLogin_CgiEntry and possibly other unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allow remote attackers to hijack the authentication of administrators for requests that (1) restore factory settings or (2) reboot the device via…
- risk 0.40cvss 6.1epss 0.01
CRLF injection vulnerability in Huawei FusionAccess before V100R006C00 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the email APP in Huawei PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92 before AL10C92B211; ATH smartphones with software AL00C00 before AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361, and…
- risk 0.40cvss 6.1epss 0.01
The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B350, GRA-TL00 before GRA-TL00C01B350, GRA-CL00 before GRA-CL00C92B350, and GRA-CL10 before GRA-CL10C92B350 and Mate S smartphones with software CRR-TL00 before…
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in an unspecified portal authentication page in Huawei Agile Controller-Campus with software before V100R001C00SPC319 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Page 31 of 48