Vendor CVEs
Huawei
All CVEs
2,386 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17151 | Med | 0.38 | 5.9 | 0.01 | Feb 15, 2018 | Huawei AR100, AR100-S, AR110-S, AR120, AR120-S, AR1200, AR1200-S, AR150, AR150-S, AR160, AR200, AR200-S, AR2200, AR2200-S, AR3200, AR510, DP300, NetEngine16EX, RP200, SRG1300, SRG2300, SRG3300, TE30, TE40, TE50, TE60, TP3106, TP3206, ViewPoint 8660, and ViewPoint 9030 have an… | ||
| CVE-2014-5394 | Med | 0.38 | 5.9 | 0.02 | Jan 8, 2018 | Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal. | ||
| CVE-2017-8191 | Med | 0.38 | 5.9 | 0.01 | Nov 22, 2017 | FusionSphere OpenStack V100R006C00SPC102(NFV)has a week cryptographic algorithm vulnerability. Attackers may exploit the vulnerability to crack the cipher text and cause information leak on the transmission links. | ||
| CVE-2017-8157 | Med | 0.38 | 5.9 | 0.01 | Nov 22, 2017 | OceanStor 5800 V3 with software V300R002C00 and V300R002C10, OceanStor 6900 V3 V300R001C00 has an information leakage vulnerability. Products use TLS1.0 to encrypt. Attackers can exploit TLS1.0's vulnerabilities to decrypt data to obtain sensitive information. | ||
| CVE-2015-2255 | Med | 0.38 | 5.9 | 0.01 | Jun 8, 2017 | Huawei AR1220 routers with software before V200R005SPH006 allow remote attackers to cause a denial of service (board reset) via vectors involving a large amount of traffic from the GE port to the FE port. | ||
| CVE-2016-8795 | Med | 0.38 | 5.9 | 0.01 | Apr 2, 2017 | Huawei CloudEngine 12800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 5800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 6800 with software V100R002C00,… | ||
| CVE-2016-5435 | Med | 0.38 | 5.9 | 0.01 | Jun 24, 2016 | Memory leak in Huawei IPS Module, NGFW Module, NIP6300, NIP6600, and Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 V500R001C00 before V500R001C20SPC100, when in hot standby networking where two devices are not directly connected, allows remote attackers to cause… | ||
| CVE-2026-34855 | Med | 0.37 | 5.7 | 0.00 | Apr 13, 2026 | Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2026-34854 | Med | 0.37 | 5.7 | 0.00 | Apr 13, 2026 | UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2025-68967 | Med | 0.37 | 5.7 | 0.00 | Jan 14, 2026 | Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-68963 | Med | 0.37 | 5.7 | 0.00 | Jan 14, 2026 | Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-58257 | Med | 0.37 | 5.7 | 0.00 | Aug 8, 2025 | EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution. | ||
| CVE-2025-54624 | Med | 0.37 | 5.7 | 0.00 | Aug 6, 2025 | Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-54618 | Med | 0.37 | 5.7 | 0.00 | Aug 6, 2025 | Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-53168 | Med | 0.37 | 5.7 | 0.00 | Jul 7, 2025 | Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness. | ||
| CVE-2024-57958 | Med | 0.37 | 5.7 | 0.00 | Feb 6, 2025 | Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2024-56437 | Med | 0.37 | 5.7 | 0.00 | Jan 8, 2025 | Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-54111 | Med | 0.37 | 5.7 | 0.00 | Dec 12, 2024 | Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-51521 | Med | 0.37 | 5.7 | 0.00 | Nov 5, 2024 | Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2019-5211 | Med | 0.37 | 5.7 | 0.00 | Nov 29, 2019 | The Huawei Share function of P20 phones with versions earlier than Emily-L29C 9.1.0.311 has an improper file management vulnerability. The attacker tricks the victim to perform certain operations on the mobile phone during file transfer. Because the file is not properly… | ||
| CVE-2018-7930 | Med | 0.37 | 5.7 | 0.00 | Apr 11, 2018 | The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C567) has an information leak vulnerability due to insufficient validation on data transfer requests. When an affected mobile phone sends files to an attacker's… | ||
| CVE-2017-17131 | Med | 0.37 | 5.7 | 0.01 | Mar 5, 2018 | Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V600R006C00; TE50 V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00; VP9660 V500R002C10 have an DoS vulnerability due to insufficient validation of the parameter when a putty comment key is loaded.… | ||
| CVE-2016-8790 | Med | 0.37 | 5.7 | 0.00 | Apr 2, 2017 | Huawei CloudEngine 5800 with software before V200R001C00SPC700, CloudEngine 6800 with software before V200R001C00SPC700, CloudEngine 7800 with software before V200R001C00SPC700, CloudEngine 8800 with software before V200R001C00SPC700, CloudEngine 12800 with software before… | ||
| CVE-2026-49308 | Med | 0.36 | 5.5 | 0.00 | Aug 17, 2026 | Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2026-41980 | Med | 0.36 | 5.5 | 0.00 | Jun 9, 2026 | Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2026-41971 | Med | 0.36 | 5.5 | 0.00 | May 15, 2026 | Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2026-41966 | Med | 0.36 | 5.6 | 0.00 | May 15, 2026 | Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2026-34867 | Med | 0.36 | 5.6 | 0.00 | Apr 13, 2026 | Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-24927 | Med | 0.36 | 5.5 | 0.00 | Feb 6, 2026 | Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58315 | Med | 0.36 | 5.5 | 0.00 | Nov 28, 2025 | Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-58293 | Med | 0.36 | 5.5 | 0.00 | Oct 11, 2025 | Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58288 | Med | 0.36 | 5.5 | 0.00 | Oct 11, 2025 | Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58283 | Med | 0.36 | 5.5 | 0.00 | Oct 11, 2025 | Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54640 | Med | 0.36 | 5.5 | 0.00 | Aug 6, 2025 | ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions. | ||
| CVE-2025-54639 | Med | 0.36 | 5.5 | 0.00 | Aug 6, 2025 | ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions. | ||
| CVE-2025-54638 | Med | 0.36 | 5.5 | 0.00 | Aug 6, 2025 | Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of this vulnerability may affect the availability of the ad service. | ||
| CVE-2025-54620 | Med | 0.36 | 5.5 | 0.00 | Aug 6, 2025 | Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-48910 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2025 | Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-52972 | Med | 0.36 | 5.5 | 0.00 | Mar 26, 2025 | Huawei PCs have a vulnerability that allows low-privilege users to bypass SDDL permission checks . Successful exploitation this vulnerability could lead to termination of some system processes. | ||
| CVE-2024-56455 | Med | 0.36 | 5.5 | 0.00 | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-56454 | Med | 0.36 | 5.5 | 0.00 | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-56452 | Med | 0.36 | 5.5 | 0.00 | Jan 8, 2025 | Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-56442 | Med | 0.36 | 5.5 | 0.00 | Jan 8, 2025 | Vulnerability of native APIs not being implemented in the NFC service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally. | ||
| CVE-2024-56436 | Med | 0.36 | 5.5 | 0.00 | Jan 8, 2025 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-54112 | Med | 0.36 | 5.5 | 0.00 | Dec 12, 2024 | Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-51529 | Med | 0.36 | 5.5 | 0.00 | Nov 5, 2024 | Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability. | ||
| CVE-2024-51520 | Med | 0.36 | 5.5 | 0.00 | Nov 5, 2024 | Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-51513 | Med | 0.36 | 5.5 | 0.00 | Nov 5, 2024 | Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consumption. | ||
| CVE-2024-47291 | Med | 0.36 | 5.6 | 0.00 | Sep 27, 2024 | Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-47290 | Med | 0.36 | 5.5 | 0.00 | Sep 27, 2024 | Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability. |
- risk 0.38cvss 5.9epss 0.01
Huawei AR100, AR100-S, AR110-S, AR120, AR120-S, AR1200, AR1200-S, AR150, AR150-S, AR160, AR200, AR200-S, AR2200, AR2200-S, AR3200, AR510, DP300, NetEngine16EX, RP200, SRG1300, SRG2300, SRG3300, TE30, TE40, TE50, TE60, TP3106, TP3206, ViewPoint 8660, and ViewPoint 9030 have an…
- risk 0.38cvss 5.9epss 0.02
Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal.
- risk 0.38cvss 5.9epss 0.01
FusionSphere OpenStack V100R006C00SPC102(NFV)has a week cryptographic algorithm vulnerability. Attackers may exploit the vulnerability to crack the cipher text and cause information leak on the transmission links.
- risk 0.38cvss 5.9epss 0.01
OceanStor 5800 V3 with software V300R002C00 and V300R002C10, OceanStor 6900 V3 V300R001C00 has an information leakage vulnerability. Products use TLS1.0 to encrypt. Attackers can exploit TLS1.0's vulnerabilities to decrypt data to obtain sensitive information.
- risk 0.38cvss 5.9epss 0.01
Huawei AR1220 routers with software before V200R005SPH006 allow remote attackers to cause a denial of service (board reset) via vectors involving a large amount of traffic from the GE port to the FE port.
- risk 0.38cvss 5.9epss 0.01
Huawei CloudEngine 12800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 5800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 6800 with software V100R002C00,…
- risk 0.38cvss 5.9epss 0.01
Memory leak in Huawei IPS Module, NGFW Module, NIP6300, NIP6600, and Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 V500R001C00 before V500R001C20SPC100, when in hot standby networking where two devices are not directly connected, allows remote attackers to cause…
- risk 0.37cvss 5.7epss 0.00
Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.37cvss 5.7epss 0.00
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.37cvss 5.7epss 0.00
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.37cvss 5.7epss 0.00
Man-in-the-middle attack vulnerability in the Clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.37cvss 5.7epss 0.00
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.
- risk 0.37cvss 5.7epss 0.00
Unexpected injection event vulnerability in the multimodalinput module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.37cvss 5.7epss 0.00
Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.37cvss 5.7epss 0.00
Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful exploitation of this vulnerability may allow the peer device to use the camera without user awareness.
- risk 0.37cvss 5.7epss 0.00
Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.37cvss 5.7epss 0.00
Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.37cvss 5.7epss 0.00
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.37cvss 5.7epss 0.00
Input parameter verification vulnerability in the background service module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.37cvss 5.7epss 0.00
The Huawei Share function of P20 phones with versions earlier than Emily-L29C 9.1.0.311 has an improper file management vulnerability. The attacker tricks the victim to perform certain operations on the mobile phone during file transfer. Because the file is not properly…
- risk 0.37cvss 5.7epss 0.00
The Near Field Communication (NFC) module in Mate 9 Huawei mobile phones with the versions before MHA-L29B 8.0.0.366(C567) has an information leak vulnerability due to insufficient validation on data transfer requests. When an affected mobile phone sends files to an attacker's…
- risk 0.37cvss 5.7epss 0.01
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V600R006C00; TE50 V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00; VP9660 V500R002C10 have an DoS vulnerability due to insufficient validation of the parameter when a putty comment key is loaded.…
- risk 0.37cvss 5.7epss 0.00
Huawei CloudEngine 5800 with software before V200R001C00SPC700, CloudEngine 6800 with software before V200R001C00SPC700, CloudEngine 7800 with software before V200R001C00SPC700, CloudEngine 8800 with software before V200R001C00SPC700, CloudEngine 12800 with software before…
- risk 0.36cvss 5.5epss 0.00
Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.6epss 0.00
Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.6epss 0.00
Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.
- risk 0.36cvss 5.5epss 0.00
ParcelMismatch vulnerability in attribute deserialization. Impact: Successful exploitation of this vulnerability may cause playback control screen display exceptions.
- risk 0.36cvss 5.5epss 0.00
Issue of inconsistent read/write serialization in the ad module. Impact: Successful exploitation of this vulnerability may affect the availability of the ad service.
- risk 0.36cvss 5.5epss 0.00
Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Buffer overflow vulnerability in the DFile module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Huawei PCs have a vulnerability that allows low-privilege users to bypass SDDL permission checks . Successful exploitation this vulnerability could lead to termination of some system processes.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of native APIs not being implemented in the NFC service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
- risk 0.36cvss 5.5epss 0.00
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.36cvss 5.5epss 0.00
Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Vulnerability of processes not being fully terminated in the VPN module Impact: Successful exploitation of this vulnerability will affect power consumption.
- risk 0.36cvss 5.6epss 0.00
Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.36cvss 5.5epss 0.00
Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability.
Page 33 of 48