Vendor CVEs
Huawei
All CVEs
2,397 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-6158 | Med | 0.40 | 6.1 | 0.01 | Sep 21, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allow remote attackers to hijack the authentication of administrators for requests that (1) restore factory settings or (2) reboot the device via… | ||
| CVE-2016-6839 | Med | 0.40 | 6.1 | 0.01 | Sep 7, 2016 | CRLF injection vulnerability in Huawei FusionAccess before V100R006C00 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | ||
| CVE-2016-4575 | Med | 0.40 | 6.1 | 0.01 | May 25, 2016 | Cross-site scripting (XSS) vulnerability in the email APP in Huawei PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92 before AL10C92B211; ATH smartphones with software AL00C00 before AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361, and… | ||
| CVE-2015-8682 | Med | 0.40 | 6.1 | 0.01 | Apr 13, 2016 | The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B350, GRA-TL00 before GRA-TL00C01B350, GRA-CL00 before GRA-CL00C92B350, and GRA-CL10 before GRA-CL10C92B350 and Mate S smartphones with software CRR-TL00 before… | ||
| CVE-2016-2214 | Med | 0.40 | 6.1 | 0.01 | Feb 8, 2016 | Cross-site scripting (XSS) vulnerability in an unspecified portal authentication page in Huawei Agile Controller-Campus with software before V100R001C00SPC319 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | ||
| CVE-2015-8675 | Med | 0.40 | 6.2 | 0.00 | Jan 15, 2016 | Huawei S5300 Campus Series switches with software before V200R005SPH008 do not mask the password when uploading files, which allows physically proximate attackers to obtain sensitive password information by reading the display. | ||
| CVE-2026-24919 | Med | 0.39 | 6.0 | 0.00 | Feb 6, 2026 | Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-56438 | Med | 0.39 | 6.0 | 0.00 | Jan 8, 2025 | Vulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2020-1840 | Med | 0.39 | 6.0 | 0.00 | Jan 21, 2020 | HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker with high privilege can execute a specific command to exploit this vulnerability. Successful exploitation may cause information leak… | ||
| CVE-2017-8189 | Med | 0.39 | 6.0 | 0.00 | Nov 22, 2017 | FusionSphere OpenStack V100R006C00SPC102(NFV)has a path traversal vulnerability. Due to insufficient path validation, an attacker with high privilege may exploit this vulnerability to cover some files, causing services abnormal. | ||
| CVE-2026-81646 | Med | 0.38 | 5.9 | 0.00 | Sep 9, 2026 | Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-41968 | Med | 0.38 | 5.9 | 0.00 | May 15, 2026 | Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-41967 | Med | 0.38 | 5.9 | 0.00 | May 15, 2026 | Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-41961 | Med | 0.38 | 5.9 | 0.00 | May 15, 2026 | Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-41960 | Med | 0.38 | 5.8 | 0.00 | May 15, 2026 | Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-34859 | Med | 0.38 | 5.9 | 0.00 | Apr 13, 2026 | UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2026-28546 | Med | 0.38 | 5.9 | 0.00 | Mar 5, 2026 | Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-28545 | Med | 0.38 | 5.9 | 0.00 | Mar 5, 2026 | Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-28538 | Med | 0.38 | 5.9 | 0.00 | Mar 5, 2026 | Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-24928 | Med | 0.38 | 5.8 | 0.00 | Feb 6, 2026 | Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2026-24931 | Med | 0.38 | 5.9 | 0.00 | Feb 6, 2026 | Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2026-24929 | Med | 0.38 | 5.9 | 0.00 | Feb 6, 2026 | Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-24916 | Med | 0.38 | 5.9 | 0.00 | Feb 6, 2026 | Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-58311 | Med | 0.38 | 5.8 | 0.00 | Nov 28, 2025 | UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2025-58289 | Med | 0.38 | 5.9 | 0.00 | Oct 11, 2025 | Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58297 | Med | 0.38 | 5.9 | 0.00 | Oct 11, 2025 | Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58295 | Med | 0.38 | 5.9 | 0.00 | Oct 11, 2025 | Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58284 | Med | 0.38 | 5.9 | 0.00 | Oct 11, 2025 | Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54635 | Med | 0.38 | 5.9 | 0.00 | Aug 6, 2025 | Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-54613 | Med | 0.38 | 5.9 | 0.00 | Aug 6, 2025 | Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2025-54612 | Med | 0.38 | 5.9 | 0.00 | Aug 6, 2025 | Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2025-53186 | Med | 0.38 | 5.9 | 0.00 | Jul 7, 2025 | Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-5465 | Med | 0.38 | 5.9 | 0.00 | Jun 14, 2024 | Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-32998 | Med | 0.38 | 5.9 | 0.00 | May 14, 2024 | NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2022-48613 | Med | 0.38 | 5.9 | 0.00 | Nov 8, 2023 | Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed. | ||
| CVE-2022-48509 | Med | 0.38 | 5.9 | 0.00 | Jul 6, 2023 | Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulnerability may cause the program to exit abnormally. | ||
| CVE-2022-44563 | Med | 0.38 | 5.9 | 0.00 | Nov 9, 2022 | There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-39006 | Med | 0.38 | 5.9 | 0.00 | Sep 16, 2022 | The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart. | ||
| CVE-2021-40055 | Med | 0.38 | 5.9 | 0.01 | Mar 10, 2022 | There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity. | ||
| CVE-2021-37085 | Med | 0.38 | 5.9 | 0.00 | Dec 7, 2021 | There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service. | ||
| CVE-2021-37082 | Med | 0.38 | 5.9 | 0.00 | Dec 7, 2021 | There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash. | ||
| CVE-2021-22356 | Med | 0.38 | 5.9 | 0.00 | Nov 23, 2021 | There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected… | ||
| CVE-2021-36987 | Med | 0.38 | 5.9 | 0.00 | Oct 28, 2021 | There is a issue that nodes in the linked list being freed for multiple times in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause the system to restart. | ||
| CVE-2019-5253 | Med | 0.38 | 5.9 | 0.01 | Dec 13, 2019 | E5572-855 with versions earlier than 8.0.1.3(H335SP1C233) has an improper authentication vulnerability. The device does not perform a sufficient authentication when doing certain operations, successful exploit could allow an attacker to cause the device to reboot after launch a… | ||
| CVE-2019-5291 | Med | 0.38 | 5.9 | 0.00 | Dec 13, 2019 | Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient… | ||
| CVE-2018-7987 | Med | 0.38 | 5.9 | 0.01 | Dec 4, 2018 | There is an out-of-bounds write vulnerability on Huawei P20 smartphones with versions before 8.1.0.171(C00). The software does not handle the response message properly when the user doing certain inquiry operation, an attacker could send crafted message to the device, successful… | ||
| CVE-2018-7959 | Med | 0.38 | 5.9 | 0.01 | Nov 27, 2018 | There is a short key vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept and decrypt the call information when the user enables SRTP to make a call. Successful exploitation may cause sensitive information… | ||
| CVE-2017-17305 | Med | 0.38 | 5.9 | 0.01 | Aug 21, 2018 | Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a Bleichenbacher Oracle vulnerability in the IPSEC IKEv1 implementations. Remote attackers can decrypt IPSEC tunnel ciphertext data by… | ||
| CVE-2017-17174 | Med | 0.38 | 5.9 | 0.01 | Jul 31, 2018 | Some Huawei products RSE6500 V500R002C00; SoftCo V200R003C20SPCb00; VP9660 V600R006C10; eSpace U1981 V100R001C20; V200R003C20; V200R003C30; V200R003C50 have a weak algorithm vulnerability. To exploit the vulnerability, a remote, unauthenticated attacker has to capture TLS… | ||
| CVE-2017-17217 | Med | 0.38 | 5.9 | 0.01 | Mar 9, 2018 | Media Gateway Control Protocol (MGCP) in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an out-of-bounds… |
- risk 0.40cvss 6.1epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allow remote attackers to hijack the authentication of administrators for requests that (1) restore factory settings or (2) reboot the device via…
- risk 0.40cvss 6.1epss 0.01
CRLF injection vulnerability in Huawei FusionAccess before V100R006C00 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the email APP in Huawei PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92 before AL10C92B211; ATH smartphones with software AL00C00 before AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361, and…
- risk 0.40cvss 6.1epss 0.01
The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B350, GRA-TL00 before GRA-TL00C01B350, GRA-CL00 before GRA-CL00C92B350, and GRA-CL10 before GRA-CL10C92B350 and Mate S smartphones with software CRR-TL00 before…
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in an unspecified portal authentication page in Huawei Agile Controller-Campus with software before V100R001C00SPC319 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
- risk 0.40cvss 6.2epss 0.00
Huawei S5300 Campus Series switches with software before V200R005SPH008 do not mask the password when uploading files, which allows physically proximate attackers to obtain sensitive password information by reading the display.
- risk 0.39cvss 6.0epss 0.00
Out-of-bounds write vulnerability in the DFX module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.39cvss 6.0epss 0.00
Vulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.39cvss 6.0epss 0.00
HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker with high privilege can execute a specific command to exploit this vulnerability. Successful exploitation may cause information leak…
- risk 0.39cvss 6.0epss 0.00
FusionSphere OpenStack V100R006C00SPC102(NFV)has a path traversal vulnerability. Due to insufficient path validation, an attacker with high privilege may exploit this vulnerability to cover some files, causing services abnormal.
- risk 0.38cvss 5.9epss 0.00
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.8epss 0.00
Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.38cvss 5.9epss 0.00
Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.8epss 0.00
Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.38cvss 5.9epss 0.00
Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.38cvss 5.9epss 0.00
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
Identity authentication bypass vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.38cvss 5.8epss 0.00
UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.38cvss 5.9epss 0.00
Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.38cvss 5.9epss 0.00
Vulnerability of returning released pointers in the distributed notification service. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.38cvss 5.9epss 0.00
Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.38cvss 5.9epss 0.00
Vulnerability that allows third-party call apps to send broadcasts without verification in the audio framework module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.38cvss 5.9epss 0.00
Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.38cvss 5.9epss 0.00
NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.38cvss 5.9epss 0.00
Race condition vulnerability in the kernel module. Successful exploitation of this vulnerability may cause variable values to be read with the condition evaluation bypassed.
- risk 0.38cvss 5.9epss 0.00
Race condition vulnerability due to multi-thread access to mutually exclusive resources in Huawei Share. Successful exploitation of this vulnerability may cause the program to exit abnormally.
- risk 0.38cvss 5.9epss 0.00
There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.38cvss 5.9epss 0.00
The MPTCP module has the race condition vulnerability. Successful exploitation of this vulnerability may cause the device to restart.
- risk 0.38cvss 5.9epss 0.01
There is a man-in-the-middle attack vulnerability during system update download in recovery mode. Successful exploitation of this vulnerability may affect integrity.
- risk 0.38cvss 5.9epss 0.00
There is a Encoding timing vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of service.
- risk 0.38cvss 5.9epss 0.00
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to motionhub crash.
- risk 0.38cvss 5.9epss 0.00
There is a weak secure algorithm vulnerability in Huawei products. A weak secure algorithm is used in a module. Attackers can exploit this vulnerability by capturing and analyzing the messages between devices to obtain information. This can lead to information leak.Affected…
- risk 0.38cvss 5.9epss 0.00
There is a issue that nodes in the linked list being freed for multiple times in Huawei Smartphone due to race conditions. Successful exploitation of this vulnerability can cause the system to restart.
- risk 0.38cvss 5.9epss 0.01
E5572-855 with versions earlier than 8.0.1.3(H335SP1C233) has an improper authentication vulnerability. The device does not perform a sufficient authentication when doing certain operations, successful exploit could allow an attacker to cause the device to reboot after launch a…
- risk 0.38cvss 5.9epss 0.00
Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient…
- risk 0.38cvss 5.9epss 0.01
There is an out-of-bounds write vulnerability on Huawei P20 smartphones with versions before 8.1.0.171(C00). The software does not handle the response message properly when the user doing certain inquiry operation, an attacker could send crafted message to the device, successful…
- risk 0.38cvss 5.9epss 0.01
There is a short key vulnerability in Huawei eSpace product. An unauthenticated, remote attacker launches man-in-the-middle attack to intercept and decrypt the call information when the user enables SRTP to make a call. Successful exploitation may cause sensitive information…
- risk 0.38cvss 5.9epss 0.01
Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a Bleichenbacher Oracle vulnerability in the IPSEC IKEv1 implementations. Remote attackers can decrypt IPSEC tunnel ciphertext data by…
- risk 0.38cvss 5.9epss 0.01
Some Huawei products RSE6500 V500R002C00; SoftCo V200R003C20SPCb00; VP9660 V600R006C10; eSpace U1981 V100R001C20; V200R003C20; V200R003C30; V200R003C50 have a weak algorithm vulnerability. To exploit the vulnerability, a remote, unauthenticated attacker has to capture TLS…
- risk 0.38cvss 5.9epss 0.01
Media Gateway Control Protocol (MGCP) in Huawei DP300 V500R002C00; RP200 V500R002C00SPC200; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 has an out-of-bounds…
Page 32 of 48