VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2015-8675MedJan 15, 2016
    risk 0.40cvss 6.2epss 0.00

    Huawei S5300 Campus Series switches with software before V200R005SPH008 do not mask the password when uploading files, which allows physically proximate attackers to obtain sensitive password information by reading the display.

  • CVE-2026-24919MedFeb 6, 2026
    risk 0.39cvss 6.0epss 0.00

    Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-56438MedJan 8, 2025
    risk 0.39cvss 6.0epss 0.00

    Vulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2020-1840MedJan 21, 2020
    risk 0.39cvss 6.0epss 0.00

    HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker with high privilege can execute a specific command to exploit this vulnerability. Successful exploitation may cause information leak…

  • CVE-2017-8189MedNov 22, 2017
    risk 0.39cvss 6.0epss 0.00

    FusionSphere OpenStack V100R006C00SPC102(NFV)has a path traversal vulnerability. Due to insufficient path validation, an attacker with high privilege may exploit this vulnerability to cover some files, causing services abnormal.

  • CVE-2026-41968MedMay 15, 2026
    risk 0.38cvss 5.9epss 0.00

    Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-41967MedMay 15, 2026
    risk 0.38cvss 5.9epss 0.00

    Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-41961MedMay 15, 2026
    risk 0.38cvss 5.9epss 0.00

    Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-41960MedMay 15, 2026
    risk 0.38cvss 5.8epss 0.00

    Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-34859MedApr 13, 2026
    risk 0.38cvss 5.9epss 0.00

    UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2026-28546MedMar 5, 2026
    risk 0.38cvss 5.9epss 0.00

    Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-28545MedMar 5, 2026
    risk 0.38cvss 5.9epss 0.00

    Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-28538MedMar 5, 2026
    risk 0.38cvss 5.9epss 0.00

    Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-24928MedFeb 6, 2026
    risk 0.38cvss 5.8epss 0.00

    Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-24931MedFeb 6, 2026
    risk 0.38cvss 5.9epss 0.00

    Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-24929MedFeb 6, 2026
    risk 0.38cvss 5.9epss 0.00

    Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-24916MedFeb 6, 2026
    risk 0.38cvss 5.9epss 0.00

    Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-58311MedNov 28, 2025
    risk 0.38cvss 5.8epss 0.00

    UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2025-58289MedOct 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58297MedOct 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58295MedOct 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58284MedOct 11, 2025
    risk 0.38cvss 5.9epss 0.00

    Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54635MedAug 6, 2025
    risk 0.38cvss 5.9epss 0.00

    Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54613MedAug 6, 2025
    risk 0.38cvss 5.9epss 0.00

    Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-54612MedAug 6, 2025
    risk 0.38cvss 5.9epss 0.00

    Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-53186MedJul 7, 2025
    risk 0.38cvss 5.9epss 0.00

    Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-5465MedJun 14, 2024
    risk 0.38cvss 5.9epss 0.00

    Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-32998MedMay 14, 2024
    risk 0.38cvss 5.9epss 0.00

    NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2022-48613MedNov 8, 2023
    risk 0.38cvss 5.9epss 0.00

    Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed.

  • CVE-2022-48509MedJul 6, 2023
    risk 0.38cvss 5.9epss 0.00

    Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulnerability may cause the program to exit abnormally.

  • CVE-2022-44563MedNov 9, 2022
    risk 0.38cvss 5.9epss 0.00

    There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-39006MedSep 16, 2022
    risk 0.38cvss 5.9epss 0.00

    The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.

  • CVE-2021-40055MedMar 10, 2022
    risk 0.38cvss 5.9epss 0.01

    There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity.

  • CVE-2021-37085MedDec 7, 2021
    risk 0.38cvss 5.9epss 0.00

    There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service.

  • CVE-2021-37082MedDec 7, 2021
    risk 0.38cvss 5.9epss 0.00

    There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash.

  • CVE-2021-22356MedNov 23, 2021
    risk 0.38cvss 5.9epss 0.00

    There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected…

  • CVE-2021-36987MedOct 28, 2021
    risk 0.38cvss 5.9epss 0.00

    There is a issue that nodes in the linked list being freed for multiple times in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause the system to restart.

  • CVE-2019-5253MedDec 13, 2019
    risk 0.38cvss 5.9epss 0.01

    E5572-855 with versions earlier than 8.0.1.3(H335SP1C233) has an improper authentication vulnerability. The device does not perform a sufficient authentication when doing certain operations, successful exploit could allow an attacker to cause the device to reboot after launch a…

  • CVE-2019-5291MedDec 13, 2019
    risk 0.38cvss 5.9epss 0.00

    Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient…

  • CVE-2018-7987MedDec 4, 2018
    risk 0.38cvss 5.9epss 0.01

    There is an out-of-bounds write vulnerability on Huawei P20 smartphones with versions before 8.1.0.171(C00). The software does not handle the response message properly when the user doing certain inquiry operation, an attacker could send crafted message to the device, successful…

  • CVE-2018-7959MedNov 27, 2018
    risk 0.38cvss 5.9epss 0.01

    There is a short key vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept and decrypt the call information when the user enables SRTP to make a call. Successful exploitation may cause sensitive information…

  • CVE-2017-17305MedAug 21, 2018
    risk 0.38cvss 5.9epss 0.01

    Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a Bleichenbacher Oracle vulnerability in the IPSEC IKEv1 implementations. Remote attackers can decrypt IPSEC tunnel ciphertext data by…

  • CVE-2017-17174MedJul 31, 2018
    risk 0.38cvss 5.9epss 0.01

    Some Huawei products RSE6500 V500R002C00; SoftCo V200R003C20SPCb00; VP9660 V600R006C10; eSpace U1981 V100R001C20; V200R003C20; V200R003C30; V200R003C50 have a weak algorithm vulnerability. To exploit the vulnerability, a remote, unauthenticated attacker has to capture TLS…

  • CVE-2017-17217MedMar 9, 2018
    risk 0.38cvss 5.9epss 0.01

    Media Gateway Control Protocol (MGCP) in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an out-of-bounds…

  • CVE-2017-17216MedMar 9, 2018
    risk 0.38cvss 5.9epss 0.01

    Media Gateway Control Protocol (MGCP) in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds…

  • CVE-2017-17200MedMar 9, 2018
    risk 0.38cvss 5.9epss 0.01

    Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds read vulnerability due to the improper processing…

  • CVE-2017-17199MedMar 9, 2018
    risk 0.38cvss 5.9epss 0.01

    Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds read vulnerability due to the improper processing…

  • CVE-2017-17167MedMar 9, 2018
    risk 0.38cvss 5.9epss 0.01

    Huawei DP300 V500R002C00; TP3206 V100R002C00; ViewPoint 9030 V100R011C02; V100R011C03 have a use of a broken or risky cryptographic algorithm vulnerability. The software uses risky cryptographic algorithm in SSL. This is dangerous because a remote unauthenticated attacker could…

  • CVE-2017-17160MedFeb 15, 2018
    risk 0.38cvss 5.9epss 0.01

    Huawei AR120-S V200R006C10, V200R007C00, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C02, AR1200-S V200R006C10, V200R007C00, V200R008C20, AR150 V200R006C10, V200R007C00, V200R007C02, AR150-S V200R006C10, V200R007C00, AR160 V200R006C10, V200R006C12, V200R007C00,…

  • CVE-2017-17152MedFeb 15, 2018
    risk 0.38cvss 5.9epss 0.01

    IKEv2 in Huawei IPS Module V500R001C00, V500R001C00SPC200, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078,…

Page 32 of 48