VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2017-2739LowNov 22, 2017
    risk 0.20cvss 3.1epss 0.00

    The upgrade package of Huawei Vmall APP Earlier than HwVmall 1.5.3.0 versions is transferred through HTTP. A man in the middle (MITM) can tamper with the upgrade package of Huawei Vmall APP, and to implant the malicious applications.

  • CVE-2026-41963LowMay 15, 2026
    risk 0.18cvss 2.8epss 0.00

    Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58282LowOct 11, 2025
    risk 0.18cvss 2.8epss 0.00

    Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-57956LowFeb 6, 2025
    risk 0.18cvss 2.8epss 0.00

    Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-41986LowJun 9, 2026
    risk 0.16cvss 2.4epss 0.00

    Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-34849LowApr 13, 2026
    risk 0.16cvss 2.5epss 0.00

    UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-42036LowAug 8, 2024
    risk 0.16cvss 2.5epss 0.00

    Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2020-9083LowSep 3, 2020
    risk 0.16cvss 2.4epss 0.00

    HUAWEI Mate 20 smart phones with Versions earlier than 10.1.0.163(C00E160R3P8) have a denial of service (DoS) vulnerability. The attacker can enter a large amount of text on the phone. Due to insufficient verification of the parameter, successful exploitation can impact the…

  • CVE-2020-9251LowJul 27, 2020
    risk 0.16cvss 2.4epss 0.00

    HUAWEI Mate 20 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have an improper authorization vulnerability. The software does not properly restrict certain operation in certain scenario, the attacker should do certain configuration before the user turns on…

  • CVE-2020-1831LowMay 29, 2020
    risk 0.16cvss 2.4epss 0.00

    HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.195(SP31C00E74R3P8) have an improper authorization vulnerability. The digital balance function does not sufficiently restrict the using time of certain user, successful exploit could allow the user break the limit of…

  • CVE-2020-1833LowMay 29, 2020
    risk 0.16cvss 2.4epss 0.00

    Honor 9X smartphones with versions earlier than 9.1.1.172(C00E170R8P1) have an improper authentication vulnerability. A logic error occurs when handling clock function, an attacker should do a series of crafted operations quickly before the phone is unlocked, successful exploit…

  • CVE-2020-1797LowMay 29, 2020
    risk 0.16cvss 2.4epss 0.00

    HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.185(C00E74R3P8) have an improper authorization vulnerability. The system does not properly restrict certain operation in ADB mode, successful exploit could allow certain user break the limit of digital balance function.

  • CVE-2020-9073LowMay 15, 2020
    risk 0.16cvss 2.4epss 0.00

    Huawei P20 smartphones with versions earlier than 10.0.0.156(C00E156R1P4) have an improper authentication vulnerability. The vulnerability is due to that when an user wants to do certain operation, the software insufficiently validate the user's identity. Attackers need to…

  • CVE-2020-1795LowMar 20, 2020
    risk 0.16cvss 2.4epss 0.00

    There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Digital Balance limit after a series of operations.Affected…

  • CVE-2020-1791LowFeb 18, 2020
    risk 0.16cvss 2.4epss 0.00

    HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.185(C00E74R3P8) have an improper authorization vulnerability. The system has a logic judging error under certain scenario, successful exploit could allow the attacker to switch to third desktop after a series of…

  • CVE-2019-5308LowNov 29, 2019
    risk 0.16cvss 2.4epss 0.00

    Mate 20 RS smartphones with versions earlier than 9.1.0.135(C786E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation in ADB mode, successful exploit could allow the attacker to switch to third desktop after a series of…

  • CVE-2019-5213LowNov 12, 2019
    risk 0.16cvss 2.4epss 0.00

    Honor play smartphones with versions earlier than Cornell-AL00A 9.1.0.321(C00E320R1P1T8) have an insufficient authentication vulnerability. The system has a logic judge error under certain scenario. Successful exploit could allow the attacker to modify the alarm clock settings…

  • CVE-2018-7924LowOct 17, 2018
    risk 0.16cvss 2.4epss 0.00

    Anne-AL00 Huawei phones with versions earlier than 8.0.0.151(C00) have an information leak vulnerability. Due to improper permission settings for specific commands, attackers who can connect to a mobile phone via the USB interface may exploit this vulnerability to obtain…

  • CVE-2017-2705LowNov 22, 2017
    risk 0.16cvss 2.4epss 0.00

    Huawei P9 smartphones with software versions earlier before EVA-AL10C00B365, versions earlier before EVA-AL00C00B365, versions earlier before EVA-CL00C92B365, versions earlier before EVA-DL00C17B365, versions earlier before EVA-TL00C01B365 have a phone activation bypass…

  • CVE-2020-9252LowJul 17, 2020
    risk 0.15cvss 2.3epss 0.00

    HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Honor Magic2 smartphones versions earlier than 10.1.0.160(C00E160R2P11) have a path…

  • CVE-2017-15307LowDec 22, 2017
    risk 0.15cvss 2.3epss 0.00

    Huawei Honor 8 smartphone with software versions earlier than FRD-L04C567B389 and earlier than FRD-L14C567B389 have a permission control vulnerability due to improper authorization configuration on specific device information.

  • CVE-2017-8118LowNov 22, 2017
    risk 0.15cvss 2.3epss 0.00

    The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.

  • CVE-2026-34851LowApr 13, 2026
    risk 0.14cvss 2.2epss 0.00

    Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-34850LowApr 13, 2026
    risk 0.12cvss 1.9epss 0.00

    Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2015-7254Nov 7, 2015
    risk 0.05cvss epss 0.28

    Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI.

  • CVE-2014-9418Dec 24, 2014
    risk 0.03cvss epss 0.01

    The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users to cause a denial of service (memory overflow) via unspecified vectors.

  • CVE-2014-9417Dec 24, 2014
    risk 0.03cvss epss 0.01

    The Meeting component in Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted image.

  • CVE-2014-9416Dec 24, 2014
    risk 0.03cvss epss 0.01

    Multiple untrusted search path vulnerabilities in Huawei eSpace Desktop before V200R003C00 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) mfc71enu.dll, (2) mfc71loc.dll, (3) tcapi.dll, or (4) airpcap.dll.

  • CVE-2014-9415Dec 24, 2014
    risk 0.03cvss epss 0.01

    Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QES file.

  • CVE-2014-5395Nov 21, 2014
    risk 0.03cvss epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the…

  • CVE-2014-8359Nov 13, 2014
    risk 0.03cvss epss 0.01

    Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll in the Mobile Partner directory.

  • CVE-2014-2946Jun 2, 2014
    risk 0.03cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API operations and send SMS…

  • CVE-2013-6031Mar 11, 2014
    risk 0.03cvss epss 0.06

    The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remote attackers to change passwords and settings, or obtain sensitive information, via a direct request to (1) api/wlan/security-settings, (2)…

  • CVE-2013-4631Jun 20, 2013
    risk 0.03cvss epss 0.04

    Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 is enabled, allow remote attackers to cause a denial of service (device crash) via malformed SNMPv3 requests that leverage unspecified overflow issues.

  • CVE-2013-4630Jun 20, 2013
    risk 0.03cvss epss 0.04

    Stack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allows remote attackers to execute arbitrary code via malformed SNMPv3 requests.

  • CVE-2012-6568Jun 20, 2013
    risk 0.03cvss epss 0.01

    Buffer overflow in the back-end component in Huawei UTPS 1.0 allows local users to gain privileges via a long IDS_PLUGIN_NAME string in a plug-in configuration file.

  • CVE-2012-4960Jun 20, 2013
    risk 0.03cvss epss 0.03

    The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E,…

  • CVE-2009-4197Dec 4, 2009
    risk 0.03cvss epss 0.00

    rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically proximate attackers to obtain the password from web browsers…

  • CVE-2009-4196Dec 4, 2009
    risk 0.03cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in multiple scripts in Forms/ in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 allow remote attackers to inject arbitrary web script or HTML via the (1) BackButton parameter to error_1; (2) wzConnFlag parameter to…

  • CVE-2026-58559MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.00

    DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-58557MedJul 15, 2026
    risk 0.00cvss 4.8epss 0.00

    Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-58556MedJul 15, 2026
    risk 0.00cvss 5.1epss 0.00

    Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-58555MedJul 15, 2026
    risk 0.00cvss 6.6epss 0.00

    Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-58554MedJul 15, 2026
    risk 0.00cvss 6.6epss 0.00

    Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-58553MedJul 15, 2026
    risk 0.00cvss 4.0epss 0.00

    Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-58552MedJul 15, 2026
    risk 0.00cvss 5.1epss 0.00

    Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-58551MedJul 15, 2026
    risk 0.00cvss 5.1epss 0.00

    Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-58550MedJul 15, 2026
    risk 0.00cvss 4.0epss 0.00

    Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-58549MedJul 15, 2026
    risk 0.00cvss 4.0epss 0.00

    Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2015-8084Dec 7, 2015
    risk 0.00cvss epss 0.01

    Huawei USG5500, USG2100, USG2200, and USG5100 unified security gateways with software before V300R001C10SPC600, when "DHCP Snooping" is enabled and either "option82 insert" or "option82 rebuild" is enabled on an interface, allow remote attackers to cause a denial of service…

Page 47 of 48