VYPR

Vendor CVEs

Huawei

All CVEs

2,397 total · sorted by risk
  • CVE-2017-17326MedMar 9, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei Mate 9 Pro Smartphones with software of LON-AL00BC00B139D; LON-AL00BC00B229 have an activation lock bypass vulnerability. The smartphone is supposed to be activated by the former account after reset if find my phone function is on. The software does not have a sufficient…

  • CVE-2017-17145MedMar 9, 2018
    risk 0.30cvss 4.6epss 0.00

    Huawei Honor V9 Play smart phones with the versions before Jimmy-AL00AC00B135 have an authentication bypass vulnerability due to the improper design of a component. An attacker who get a user's smart phone can execute specific operation, and delete the fingerprint of the phone…

  • CVE-2017-8173MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    Maya-L02,VKY-L09,VTR-L29,Vicky-AL00A,Victoria-AL00A,Warsaw-AL00 smart phones with software of earlier than Maya-L02C636B126 versions,earlier than VKY-L29C10B151 versions,earlier than VTR-L29C10B151 versions,earlier than Vicky-AL00AC00B162 versions,earlier than…

  • CVE-2017-8171MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    Huawei smart phones with software earlier than Vicky-AL00AC00B172D versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the Talkback mode and…

  • CVE-2017-8161MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    EVA-L09 smartphones with software Earlier than EVA-L09C25B150CUSTC25D003 versions,Earlier than EVA-L09C440B140 versions,Earlier than EVA-L09C464B361 versions,Earlier than EVA-L09C675B320CUSTC675D004 versions have Factory Reset Protection (FRP) bypass security vulnerability. When…

  • CVE-2017-8152MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have a Factory Reset Protection (FRP) bypass security vulnerability due to the improper design. An attacker can access factory reset page without authorization by only dial with special code. The…

  • CVE-2017-2721MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-L02C432B120,FRD-L02C635B1…

  • CVE-2017-2710MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    BTV-W09C229B002CUSTC229D005,BTV-W09C233B029, earlier than BTV-W09C100B006CUSTC100D002 versions, earlier than BTV-W09C128B003CUSTC128D002 versions, earlier than BTV-W09C199B002CUSTC199D002 versions, earlier than BTV-W09C209B005CUSTC209D001 versions, earlier than…

  • CVE-2017-2708MedNov 22, 2017
    risk 0.30cvss 4.6epss 0.00

    The 'Find Phone' function in Nice smartphones with software versions earlier before Nice-AL00C00B0135 has an authentication bypass vulnerability. An unauthenticated attacker may wipe and factory reset the phone by special steps. Due to missing authentication of the 'Find Phone'…

  • CVE-2015-7846MedSep 25, 2017
    risk 0.30cvss 4.6epss 0.00

    Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information.

  • CVE-2016-8776MedApr 2, 2017
    risk 0.30cvss 4.6epss 0.00

    Huawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phones with software VNS-L21C185 allow attackers to bypass the factory reset protection (FRP) to enter some functional modules without authorization and perform operations to update the…

  • CVE-2015-2808LowApr 1, 2015
    risk 0.30cvss 3.7epss 0.74

    The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing…

  • CVE-2026-28543MedMar 5, 2026
    risk 0.29cvss 4.4epss 0.00

    Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58279MedDec 8, 2025
    risk 0.29cvss 4.4epss 0.00

    Permission control vulnerability in the media library module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-64315MedNov 28, 2025
    risk 0.29cvss 4.4epss 0.00

    Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability may affect app data confidentiality and integrity.

  • CVE-2024-58256MedAug 8, 2025
    risk 0.29cvss 4.5epss 0.00

    EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

  • CVE-2025-54649MedAug 6, 2025
    risk 0.29cvss 4.5epss 0.00

    Vulnerability of using incompatible types to access resources in the location service. Impact: Successful exploitation of this vulnerability may cause some location information attributes to be incorrect.

  • CVE-2025-54637MedAug 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54636MedAug 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Issue of buffer overflow caused by insufficient data verification in the kernel drop detection module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54626MedAug 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Pointer dangling vulnerability in the cjwindow module. Impact: Successful exploitation of this vulnerability may affect function stability.

  • CVE-2025-48904MedJun 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-46592MedMay 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Null pointer dereference vulnerability in the USB HDI driver module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-46589MedMay 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2025-46588MedMay 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Vulnerability of unauthorized access in the app lock module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2023-52954MedJan 8, 2025
    risk 0.29cvss 4.4epss 0.00

    Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-56434MedJan 8, 2025
    risk 0.29cvss 4.4epss 0.00

    UAF vulnerability in the device node access module Impact: Successful exploitation of this vulnerability may cause service exceptions of the device.

  • CVE-2024-54114MedDec 12, 2024
    risk 0.29cvss 4.4epss 0.00

    Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-47294MedSep 27, 2024
    risk 0.29cvss 4.4epss 0.00

    Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-45447MedSep 4, 2024
    risk 0.29cvss 4.4epss 0.00

    Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-42032MedAug 8, 2024
    risk 0.29cvss 4.4epss 0.00

    Access permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52106MedJan 16, 2024
    risk 0.29cvss 4.4epss 0.00

    Vulnerability of permission verification for APIs in the DownloadProviderMain module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

  • CVE-2021-22310MedMar 22, 2021
    risk 0.29cvss 4.4epss 0.00

    There is an information leakage vulnerability in some huawei products. Due to the properly storage of specific information in the log file, the attacker can obtain the information when a user logs in to the device. Successful exploit may cause an information leak. Affected…

  • CVE-2020-9202MedDec 24, 2020
    risk 0.29cvss 4.4epss 0.00

    There is an information disclosure vulnerability in TE Mobile software versions V600R006C10,V600R006C10SPC100. Due to the improper storage of some information in certain specific scenario, the attacker can gain information in the victim's device to launch the attack, successful…

  • CVE-2020-9128MedNov 12, 2020
    risk 0.29cvss 4.4epss 0.00

    FusionCompute versions 8.0.0 have an insecure encryption algorithm vulnerability. Attackers with high permissions can exploit this vulnerability to cause information leak.

  • CVE-2020-9111MedOct 19, 2020
    risk 0.29cvss 4.5epss 0.00

    E6878-370 versions 10.0.3.1(H557SP27C233),10.0.3.1(H563SP21C233) and E6878-870 versions 10.0.3.1(H557SP27C233),10.0.3.1(H563SP11C233) have a denial of service vulnerability. The system does not properly check some events, an attacker could launch the events continually,…

  • CVE-2020-9229MedAug 14, 2020
    risk 0.29cvss 4.4epss 0.00

    FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, attackers may exploit this vulnerability to obtain certain information.

  • CVE-2020-1877MedFeb 28, 2020
    risk 0.29cvss 4.4epss 0.00

    NIP6800;Secospace USG6600;USG9500 with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an invalid pointer access vulnerability. The software system access an invalid pointer when administrator log in to the device and performs some operations. Successful…

  • CVE-2020-1861MedFeb 28, 2020
    risk 0.29cvss 4.4epss 0.00

    CloudEngine 12800 with versions of V200R001C00SPC600,V200R001C00SPC700,V200R002C01,V200R002C50SPC800,V200R002C50SPC800PWE,V200R003C00SPC810,V200R003C00SPC810PWE,V200R005C00SPC600,V200R005C00SPC800,V200R005C00SPC800PWE,V200R005C10,V200R005C10SPC300 have an information leakage…

  • CVE-2020-1826MedJan 9, 2020
    risk 0.29cvss 4.4epss 0.00

    Huawei Honor Magic2 mobile phones with versions earlier than 10.0.0.175(C00E59R2P11) have an information leak vulnerability. Due to a module using weak encryption tool, an attacker with the root permission may exploit the vulnerability to obtain some information.

  • CVE-2018-7901MedApr 30, 2018
    risk 0.29cvss 4.4epss 0.01

    RCS module in Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129, BLA-AL00B smart phones with software versions earlier than 8.0.0.129 has a remote control vulnerability. An attacker can trick a user to install a malicious application. When the…

  • CVE-2026-81644MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-41983MedJun 9, 2026
    risk 0.28cvss 4.3epss 0.00

    Null pointer dereference vulnerability in the browser module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-56445MedJan 8, 2025
    risk 0.28cvss 4.3epss 0.00

    Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2020-9086MedDec 27, 2024
    risk 0.28cvss 4.3epss 0.00

    There is a buffer error vulnerability in some Huawei product. An unauthenticated attacker may send special UPNP message to the affected products. Due to insufficient input validation of some value, successful exploit may cause some service abnormal. (Vulnerability ID:…

  • CVE-2024-54116MedDec 12, 2024
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2024-54115MedDec 12, 2024
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-42039MedSep 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Access control vulnerability in the SystemUI module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52544MedApr 8, 2024
    risk 0.28cvss 4.3epss 0.00

    Vulnerability of file path verification being bypassed in the email module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52380MedFeb 18, 2024
    risk 0.28cvss 4.3epss 0.00

    Vulnerability of improper access control in the email module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-44110MedOct 11, 2023
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds access vulnerability in the audio module.Successful exploitation of this vulnerability may affect availability.

Page 43 of 48