Vendor CVEs
Huawei
All CVEs
2,386 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-64311 | Med | 0.33 | 5.1 | 0.00 | Nov 28, 2025 | Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-58312 | Med | 0.33 | 5.1 | 0.00 | Nov 28, 2025 | Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-58313 | Med | 0.33 | 5.1 | 0.00 | Sep 5, 2025 | Race condition vulnerability in the device standby module. Impact: Successful exploitation of this vulnerability may cause feature exceptions of the device standby module. | ||
| CVE-2024-58255 | Med | 0.33 | 5.0 | 0.00 | Aug 8, 2025 | EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution. | ||
| CVE-2025-54646 | Med | 0.33 | 5.1 | 0.00 | Aug 6, 2025 | Vulnerability of inadequate packet length check in the BLE module. Impact: Successful exploitation of this vulnerability may affect performance. | ||
| CVE-2025-54645 | Med | 0.33 | 5.0 | 0.00 | Aug 6, 2025 | Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-46593 | Med | 0.33 | 5.1 | 0.00 | May 6, 2025 | Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2025-46586 | Med | 0.33 | 5.1 | 0.00 | May 6, 2025 | Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-58049 | Med | 0.33 | 5.0 | 0.00 | Mar 4, 2025 | Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-58047 | Med | 0.33 | 5.0 | 0.00 | Mar 4, 2025 | Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-54105 | Med | 0.33 | 5.1 | 0.00 | Dec 12, 2024 | Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2024-51527 | Med | 0.33 | 5.1 | 0.00 | Nov 5, 2024 | Permission control vulnerability in the Gallery app Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-51519 | Med | 0.33 | 5.0 | 0.00 | Nov 5, 2024 | Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-51517 | Med | 0.33 | 5.1 | 0.00 | Nov 5, 2024 | Vulnerability of improper memory access in the phone service module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-45449 | Med | 0.33 | 5.1 | 0.00 | Sep 4, 2024 | Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-45442 | Med | 0.33 | 5.1 | 0.00 | Sep 4, 2024 | Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2015-2253 | Med | 0.33 | 5.0 | 0.01 | Jun 8, 2017 | The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document. | ||
| CVE-2016-8762 | Med | 0.33 | 5.0 | 0.00 | Apr 2, 2017 | The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an input validation vulnerability, which allows… | ||
| CVE-2025-66330 | Med | 0.32 | 4.9 | 0.00 | Dec 8, 2025 | App lock verification bypass vulnerability in the file management app. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-64312 | Med | 0.32 | 4.9 | 0.00 | Nov 28, 2025 | Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-58304 | Med | 0.32 | 4.9 | 0.00 | Nov 28, 2025 | Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-22341 | Med | 0.32 | 4.9 | 0.01 | Jun 29, 2021 | There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers with high privilege can exploit this vulnerability by performing some operations. This can lead to memory leak. Affected product versions include:IPS Module… | ||
| CVE-2021-22329 | Med | 0.32 | 4.9 | 0.00 | Jun 29, 2021 | There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper license management of the device, as a result, the license file can be… | ||
| CVE-2021-22383 | Med | 0.32 | 4.9 | 0.01 | Jun 22, 2021 | There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. The vulnerability is due to a message-handling function that contains an out-of-bounds read vulnerability. An attacker can exploit… | ||
| CVE-2021-22342 | Med | 0.32 | 4.9 | 0.01 | Jun 22, 2021 | There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include:… | ||
| CVE-2021-22360 | Med | 0.32 | 4.9 | 0.01 | May 27, 2021 | There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500. An authentication attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource… | ||
| CVE-2020-9205 | Med | 0.32 | 4.9 | 0.01 | Feb 6, 2021 | There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to… | ||
| CVE-2020-1883 | Med | 0.32 | 4.9 | 0.01 | Jun 5, 2020 | Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exploits this vulnerability by continuously performing specific operations. Successful exploitation of this vulnerability can cause service abnormal. | ||
| CVE-2019-5272 | Med | 0.32 | 4.9 | 0.00 | Dec 26, 2019 | USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with high privilege to make malicious modifications without detection. | ||
| CVE-2017-17303 | Med | 0.32 | 4.9 | 0.01 | Mar 9, 2018 | Huawei DP300 V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00B012; V500R002C00B013; V500R002C00B014; V500R002C00B017; V500R002C00B018; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC500; V500R002C00SPC600; V500R002C00SPC800;… | ||
| CVE-2015-8086 | Med | 0.32 | 4.9 | 0.00 | Oct 3, 2016 | Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software… | ||
| CVE-2015-8085 | Med | 0.32 | 4.9 | 0.00 | Oct 3, 2016 | Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software… | ||
| CVE-2016-2314 | Med | 0.32 | 4.9 | 0.01 | Feb 15, 2016 | GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 devices V200R002B022 Arg, allows remote authenticated users to cause a denial of service (device outage) by using the FTP MKD command to create a directory with a long name, and then using certain other commands. | ||
| CVE-2026-34857 | Med | 0.31 | 4.7 | 0.00 | Apr 13, 2026 | UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-28551 | Med | 0.31 | 4.7 | 0.00 | Mar 5, 2026 | Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2026-24921 | Med | 0.31 | 4.8 | 0.00 | Feb 6, 2026 | Address read vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality. | ||
| CVE-2025-68965 | Med | 0.31 | 4.7 | 0.00 | Jan 14, 2026 | Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-54651 | Med | 0.31 | 4.8 | 0.00 | Aug 6, 2025 | Race condition vulnerability in the kernel hufs module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2025-53178 | Med | 0.31 | 4.8 | 0.00 | Jul 7, 2025 | Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units. | ||
| CVE-2024-47293 | Med | 0.31 | 4.7 | 0.00 | Sep 27, 2024 | Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2023-52384 | Med | 0.31 | 4.7 | 0.00 | May 14, 2024 | Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2023-52383 | Med | 0.31 | 4.7 | 0.00 | May 14, 2024 | Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability. | ||
| CVE-2022-48615 | Med | 0.31 | 4.8 | 0.00 | Dec 12, 2023 | An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device information. | ||
| CVE-2022-31758 | Med | 0.31 | 4.7 | 0.00 | Jun 13, 2022 | The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-40015 | Med | 0.31 | 4.7 | 0.00 | Feb 9, 2022 | There is a race condition vulnerability in the binder driver subsystem in the kernel.Successful exploitation of this vulnerability may affect kernel stability. | ||
| CVE-2017-15346 | Med | 0.31 | 4.7 | 0.00 | Feb 15, 2018 | XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C05,S5700 V200R001C00, V200R002C00, V200R003C00, V200R003C02, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S6700 V200R001C00, V200R002C00,… | ||
| CVE-2017-15333 | Med | 0.31 | 4.7 | 0.00 | Feb 15, 2018 | XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C05,S5700 V200R001C00, V200R002C00, V200R003C00, V200R003C02, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S6700 V200R001C00, V200R002C00,… | ||
| CVE-2017-8148 | Med | 0.31 | 4.7 | 0.00 | Nov 22, 2017 | Audio driver in P9 smartphones with software The versions before EVA-AL10C00B389 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and the race condition cause null pointer accessing during the… | ||
| CVE-2024-58110 | Med | 0.30 | 4.6 | 0.00 | Apr 7, 2025 | Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability. | ||
| CVE-2024-58109 | Med | 0.30 | 4.6 | 0.00 | Apr 7, 2025 | Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability. |
- risk 0.33cvss 5.1epss 0.00
Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.33cvss 5.1epss 0.00
Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.33cvss 5.1epss 0.00
Race condition vulnerability in the device standby module. Impact: Successful exploitation of this vulnerability may cause feature exceptions of the device standby module.
- risk 0.33cvss 5.0epss 0.00
EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.
- risk 0.33cvss 5.1epss 0.00
Vulnerability of inadequate packet length check in the BLE module. Impact: Successful exploitation of this vulnerability may affect performance.
- risk 0.33cvss 5.0epss 0.00
Out-of-bounds array access issue due to insufficient data verification in the location service module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.33cvss 5.1epss 0.00
Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.33cvss 5.1epss 0.00
Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.33cvss 5.0epss 0.00
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.33cvss 5.0epss 0.00
Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.33cvss 5.1epss 0.00
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.33cvss 5.1epss 0.00
Permission control vulnerability in the Gallery app Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.33cvss 5.0epss 0.00
Vulnerability of input parameters not being verified in the HDC module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.33cvss 5.1epss 0.00
Vulnerability of improper memory access in the phone service module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.33cvss 5.1epss 0.00
Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.33cvss 5.1epss 0.00
Vulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.33cvss 5.0epss 0.01
The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document.
- risk 0.33cvss 5.0epss 0.00
The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an input validation vulnerability, which allows…
- risk 0.32cvss 4.9epss 0.00
App lock verification bypass vulnerability in the file management app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.32cvss 4.9epss 0.00
Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.32cvss 4.9epss 0.00
Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.32cvss 4.9epss 0.01
There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers with high privilege can exploit this vulnerability by performing some operations. This can lead to memory leak. Affected product versions include:IPS Module…
- risk 0.32cvss 4.9epss 0.00
There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper license management of the device, as a result, the license file can be…
- risk 0.32cvss 4.9epss 0.01
There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. The vulnerability is due to a message-handling function that contains an out-of-bounds read vulnerability. An attacker can exploit…
- risk 0.32cvss 4.9epss 0.01
There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include:…
- risk 0.32cvss 4.9epss 0.01
There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 of USG9500. An authentication attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource…
- risk 0.32cvss 4.9epss 0.01
There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may exploit this vulnerability through some operations to inject the CSV files. Due to insufficient input validation of some parameters, the attacker can exploit this vulnerability to…
- risk 0.32cvss 4.9epss 0.01
Huawei products NIP6800;Secospace USG6600;USG9500 have a memory leak vulnerability. An attacker with high privileges exploits this vulnerability by continuously performing specific operations. Successful exploitation of this vulnerability can cause service abnormal.
- risk 0.32cvss 4.9epss 0.00
USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with high privilege to make malicious modifications without detection.
- risk 0.32cvss 4.9epss 0.01
Huawei DP300 V500R002C00; V500R002C00B010; V500R002C00B011; V500R002C00B012; V500R002C00B013; V500R002C00B014; V500R002C00B017; V500R002C00B018; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC500; V500R002C00SPC600; V500R002C00SPC800;…
- risk 0.32cvss 4.9epss 0.00
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software…
- risk 0.32cvss 4.9epss 0.00
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software…
- risk 0.32cvss 4.9epss 0.01
GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 devices V200R002B022 Arg, allows remote authenticated users to cause a denial of service (device outage) by using the FTP MKD command to create a directory with a long name, and then using certain other commands.
- risk 0.31cvss 4.7epss 0.00
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.31cvss 4.7epss 0.00
Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.31cvss 4.8epss 0.00
Address read vulnerability in the HDC module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
- risk 0.31cvss 4.7epss 0.00
Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.31cvss 4.8epss 0.00
Race condition vulnerability in the kernel hufs module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.31cvss 4.8epss 0.00
Permission bypass vulnerability in the calendar storage module Impact: Successful exploitation of this vulnerability may affect the schedule reminder function of head units.
- risk 0.31cvss 4.7epss 0.00
Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.31cvss 4.7epss 0.00
Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.31cvss 4.7epss 0.00
Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.
- risk 0.31cvss 4.8epss 0.00
An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to obtain partial device information.
- risk 0.31cvss 4.7epss 0.00
The kernel module has the race condition vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.31cvss 4.7epss 0.00
There is a race condition vulnerability in the binder driver subsystem in the kernel.Successful exploitation of this vulnerability may affect kernel stability.
- risk 0.31cvss 4.7epss 0.00
XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C05,S5700 V200R001C00, V200R002C00, V200R003C00, V200R003C02, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S6700 V200R001C00, V200R002C00,…
- risk 0.31cvss 4.7epss 0.00
XML parser in Huawei S12700 V200R005C00,S1700 V200R009C00, V200R010C00,S3700 V100R006C03, V100R006C05,S5700 V200R001C00, V200R002C00, V200R003C00, V200R003C02, V200R005C00, V200R006C00, V200R007C00, V200R008C00, V200R009C00, V200R010C00,S6700 V200R001C00, V200R002C00,…
- risk 0.31cvss 4.7epss 0.00
Audio driver in P9 smartphones with software The versions before EVA-AL10C00B389 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and the race condition cause null pointer accessing during the…
- risk 0.30cvss 4.6epss 0.00
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
- risk 0.30cvss 4.6epss 0.00
Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect availability.
Page 41 of 48