VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2017-17222HigMar 9, 2018
    risk 0.57cvss 8.8epss 0.01

    Import Language Package function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after Language Package is uploaded. Due…

  • CVE-2017-17221HigMar 9, 2018
    risk 0.57cvss 8.8epss 0.01

    Import Signal Tone function in Huawei eSpace 7950 V200R003C30; eSpace 8950 V200R003C00; V200R003C30 has a remote code execution vulnerability. An authenticated, remote attacker can craft and send the packets to the affected products after the Signal Tone is uploaded. Due to…

  • CVE-2017-17285HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.01

    Bluetooth module in some Huawei mobile phones with software LON-AL00BC00B229 and earlier versions has a buffer overflow vulnerability. Due to insufficient input validation, an unauthenticated attacker may craft Bluetooth AVDTP/AVCTP messages after successful paring, causing…

  • CVE-2017-15329HigFeb 15, 2018
    risk 0.57cvss 8.8epss 0.01

    Huawei UMA V200R001C00 has a SQL injection vulnerability in the operation and maintenance module. An attacker logs in to the system as a common user and sends crafted HTTP requests that contain malicious SQL statements to the affected system. Due to a lack of input validation on…

  • CVE-2017-15313HigDec 22, 2017
    risk 0.57cvss 8.8epss 0.01

    Huawei SmartCare V200R003C10 has a CSV injection vulnerability. An remote authenticated attacker could inject malicious CSV expression to the affected device.

  • CVE-2017-15311HigDec 22, 2017
    risk 0.57cvss 8.8epss 0.01

    The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), before BLA-AL00 8.0.0.120(SP2C00), before MHA-AL00B 8.0.0.334(C00), and before LON-AL00B 8.0.0.334(C00) have a stack overflow vulnerability due…

  • CVE-2017-15308HigDec 22, 2017
    risk 0.57cvss 8.8epss 0.01

    Huawei iReader app before 8.0.2.301 has an input validation vulnerability due to insufficient validation on the URL used for loading network data. An attacker can control app access and load malicious websites created by the attacker, and the code in webpages would be loaded and…

  • CVE-2017-8195HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, remote attacker may exploit the vulnerability to execute more operations by send a crafted rest message.

  • CVE-2017-8194HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, remote attacker may exploit the vulnerability to execute more operations by send a crafted rest message.

  • CVE-2017-8138HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.00

    HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a website containing malicious scripts which may tamper with configurations and interrupt normal services.

  • CVE-2017-8135HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some…

  • CVE-2017-8134HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some…

  • CVE-2017-8133HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.02

    Huawei iManager NetEco with software V600R008C00 and V600R008C10 has a command injection vulnerability. An authenticated, remote attacker could exploit this vulnerability to send malicious packets to a target device. Successful exploit could enable a low privileged user to…

  • CVE-2017-8132HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some…

  • CVE-2017-8131HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some…

  • CVE-2017-2737HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    VCM5010 with software versions earlier before V100R002C50SPC100 has an arbitrary file upload vulnerability. The software does not validate the files that uploaded. An authenticated attacker could upload arbitrary files to the system.

  • CVE-2017-2722HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    DP300 V500R002C00,TE60 with software V100R001C01, V100R001C10, V100R003C00, V500R002C00 and V600R006C00,TP3106 with software V100R001C06 and V100R002C00,ViewPoint 9030 with software V100R011C02, V100R011C03,eCNS210_TD with software V100R004C10,eSpace 7950 with software…

  • CVE-2017-2719HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious…

  • CVE-2017-2718HigNov 22, 2017
    risk 0.57cvss 8.8epss 0.01

    FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious…

  • CVE-2015-7843HigOct 3, 2017
    risk 0.57cvss 8.8epss 0.01

    The management interface on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software before V100R003C00SPC602, RH2288A V2 with…

  • CVE-2015-8334HigAug 29, 2017
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in the Operation and Maintenance Unit (OMU) in Huawei VCN500 before V100R002C00SPC201 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.

  • CVE-2015-8332HigAug 28, 2017
    risk 0.57cvss 8.8epss 0.01

    Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows remote authenticated users to gain privileges and perform a case operation as another user via a crafted message, aka "Horizontal…

  • CVE-2015-2252HigJun 8, 2017
    risk 0.57cvss 8.8epss 0.02

    Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a crafted UDS patch with shell scripts.

  • CVE-2015-8671HigApr 2, 2017
    risk 0.57cvss 8.8epss 0.01

    Huawei LogCenter V100R001C10 could allow an authenticated attacker to tamper with requests using a tool and submit a request to the server for privilege escalation, affecting some system functions.

  • CVE-2014-9696HigApr 2, 2017
    risk 0.57cvss 8.8epss 0.01

    The Hyper Module Management (HMM) software of Huawei Tecal E9000 Chassis V100R001C00SPC160 and earlier versions allows the operator to modify the user configuration of iMana through privilege escalation.

  • CVE-2014-9695HigApr 2, 2017
    risk 0.57cvss 8.8epss 0.01

    The Hyper Module Management (HMM) software of Huawei Tecal E9000 Chassis V100R001C00SPC160 and earlier versions could allow a non-super-domain user who accesses HMM through SNMPv3 to perform operations on a server as a super-domain user.

  • CVE-2014-9694HigApr 2, 2017
    risk 0.57cvss 8.8epss 0.01

    Huawei Tecal RH1288 V2 V100R002C00SPC107 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285 V2 V100R002C00SPC115 and earlier versions, Tecal RH2265 V2 V100R002C00, Tecal RH2285H V2 V100R002C00SPC111 and earlier versions, Tecal RH2268 V2 V100R002C00, Tecal RH2288 V2…

  • CVE-2014-9137HigApr 2, 2017
    risk 0.57cvss 8.8epss 0.00

    Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SPC900 could allow an unauthenticated, remote attacker to…

  • CVE-2014-9136HigApr 2, 2017
    risk 0.57cvss 8.8epss 0.00

    Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.

  • CVE-2014-4707HigApr 2, 2017
    risk 0.57cvss 8.8epss 0.01

    Huawei Campus S7700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9300 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300 allow unauthorized users to upgrade…

  • CVE-2016-5230HigJun 30, 2016
    risk 0.57cvss 8.8epss 0.01

    Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and control partial module functions via a crafted app.

  • CVE-2016-2405HigApr 12, 2016
    risk 0.57cvss 8.8epss 0.02

    Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to gain privileges and cause a denial of service (system crash) via a crafted URL.

  • CVE-2024-58045HigMar 4, 2025
    risk 0.56cvss 8.6epss 0.00

    Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2022-32144HigDec 20, 2024
    risk 0.56cvss 8.6epss 0.00

    There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerability may lead to service abnormal. (Vulnerability ID: HWPSIRT-2022-76192) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID:…

  • CVE-2021-37086HigDec 7, 2021
    risk 0.56cvss 8.6epss 0.01

    There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers which can isolate and read synchronization files of other applications across the UID sandbox.

  • CVE-2019-5254HigDec 13, 2019
    risk 0.56cvss 8.6epss 0.01

    Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who…

  • CVE-2026-24930HigFeb 6, 2026
    risk 0.55cvss 8.4epss 0.00

    UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-24926HigFeb 6, 2026
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68960HigJan 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68957HigJan 14, 2026
    risk 0.55cvss 8.4epss 0.00

    Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66328HigDec 8, 2025
    risk 0.55cvss 8.4epss 0.00

    Multi-thread race condition vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-66324HigDec 8, 2025
    risk 0.55cvss 8.4epss 0.00

    Input verification vulnerability in the compression and decompression module. Impact: Successful exploitation of this vulnerability may affect app data integrity.

  • CVE-2025-58302HigNov 28, 2025
    risk 0.55cvss 8.4epss 0.00

    Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-58303HigNov 28, 2025
    risk 0.55cvss 8.4epss 0.00

    UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58299HigOct 11, 2025
    risk 0.55cvss 8.4epss 0.00

    Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58281HigSep 5, 2025
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds read vulnerability in the runtime interpreter module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58280HigSep 5, 2025
    risk 0.55cvss 8.4epss 0.00

    Vulnerability of exposing object heap addresses in the Ark eTS module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-54653HigAug 6, 2025
    risk 0.55cvss 8.4epss 0.00

    Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization file module.

  • CVE-2025-54652HigAug 6, 2025
    risk 0.55cvss 8.4epss 0.00

    Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality of the virtualization module.

  • CVE-2025-31175HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect service integrity.

Page 6 of 48