VYPR

Vendor CVEs

Huawei

All CVEs

2,386 total · sorted by risk
  • CVE-2025-31170HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-58127HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-58126HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-58125HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-58124HigApr 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

  • CVE-2024-58044HigMar 4, 2025
    risk 0.55cvss 8.4epss 0.00

    Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-54098HigDec 12, 2024
    risk 0.55cvss 8.5epss 0.00

    Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2024-42035HigAug 8, 2024
    risk 0.55cvss 8.4epss 0.00

    Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.

  • CVE-2024-39672HigJul 25, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

  • CVE-2024-32997HigMay 14, 2024
    risk 0.55cvss 8.4epss 0.00

    Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2021-22376HigJun 30, 2021
    risk 0.55cvss 8.4epss 0.00

    A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnerability to bypass user restrictions.

  • CVE-2017-8155HigNov 22, 2017
    risk 0.55cvss 8.4epss 0.00

    The outdoor unit of Customer Premise Equipment (CPE) product B2338-168 V100R001C00 has a no authentication vulnerability on a certain port. After accessing the network between the indoor and outdoor units of the CPE, an attacker can deliver commands to the specific port of the…

  • CVE-2017-2726HigNov 22, 2017
    risk 0.55cvss 8.4epss 0.01

    Bastet in P10 Plus and P10 smart phones with software earlier than VKY-AL00C00B123 versions, earlier than VTR-AL00C00B123 versions have a buffer overflow vulnerability. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The…

  • CVE-2017-2724HigNov 22, 2017
    risk 0.55cvss 8.4epss 0.01

    Bastet in P10 Plus and P10 smart phones with software earlier than VKY-AL00C00B123 versions, earlier than VTR-AL00C00B123 versions have a buffer overflow vulnerability. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The…

  • CVE-2025-54622HigAug 6, 2025
    risk 0.54cvss 8.3epss 0.00

    Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2014-8358HigDec 11, 2017
    risk 0.54cvss 7.8epss 0.05

    Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014) use a weak ACL for the "Mobile Partner" directory, which allows remote attackers to gain SYSTEM…

  • CVE-2015-8088HigJan 12, 2016
    risk 0.54cvss 7.8epss 0.04

    Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before MT7-TL10C00B354, MT7-TL00 before MT7-TL00C01B354, and MT7-CL00 before MT7-CL00C92B354 and P8 phones with software GRA-TL00 before…

  • CVE-2025-54655HigAug 6, 2025
    risk 0.53cvss 8.1epss 0.00

    Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization graphics module.

  • CVE-2025-48911HigJun 6, 2025
    risk 0.53cvss 8.2epss 0.00

    Vulnerability of improper permission assignment in the note sharing module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-48905HigJun 6, 2025
    risk 0.53cvss 8.1epss 0.00

    Wasm exception capture vulnerability in the arkweb v8 module Impact: Successful exploitation of this vulnerability may cause the failure to capture specific Wasm exception types.

  • CVE-2024-51526HigNov 5, 2024
    risk 0.53cvss 8.2epss 0.00

    Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-34154HigJun 16, 2023
    risk 0.53cvss 8.2epss 0.00

    Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to create windows in an arbitrary way, consuming system resources.

  • CVE-2021-37134HigJan 3, 2022
    risk 0.53cvss 8.1epss 0.00

    Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.

  • CVE-2021-37074HigDec 8, 2021
    risk 0.53cvss 8.1epss 0.01

    There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation.

  • CVE-2021-22428HigAug 2, 2021
    risk 0.53cvss 8.1epss 0.01

    There is an Incomplete Cleanup Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass.

  • CVE-2021-22427HigAug 2, 2021
    risk 0.53cvss 8.1epss 0.01

    There is a Heap-based Buffer Overflow Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass.

  • CVE-2021-22384HigAug 2, 2021
    risk 0.53cvss 8.1epss 0.01

    There is an Information Disclosure Vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to authentication bypass.

  • CVE-2021-22351HigJun 30, 2021
    risk 0.53cvss 8.1epss 0.01

    There is a Credentials Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may induce users to grant permissions on modifying items in the configuration table,causing system exceptions.

  • CVE-2021-22369HigJun 30, 2021
    risk 0.53cvss 8.1epss 0.01

    There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may escalate the permission to that of the root user.

  • CVE-2021-22439HigJun 29, 2021
    risk 0.53cvss 8.1epss 0.01

    There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request to exploit this vulnerability. Successfully exploiting this vulnerability, the attacker can execute remote malicious code injection and to control the device.

  • CVE-2020-1864HigMar 20, 2020
    risk 0.53cvss 8.1epss 0.01

    Some Huawei products have a security vulnerability due to improper authentication. A remote attacker needs to obtain some information and forge the peer device to send specific packets to the affected device. Due to the improper implementation of the authentication function,…

  • CVE-2014-2271HigJan 14, 2020
    risk 0.53cvss 8.1epss 0.02

    cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and…

  • CVE-2020-1871HigJan 3, 2020
    risk 0.53cvss 8.2epss 0.01

    USG9500 with software of V500R001C30SPC100; V500R001C30SPC200; V500R001C30SPC600; V500R001C60SPC500; V500R005C00SPC100; V500R005C00SPC200 have an improper credentials management vulnerability. The software does not properly manage certain credentials. Successful exploit could…

  • CVE-2019-5268HigNov 29, 2019
    risk 0.53cvss 8.1epss 0.00

    Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an attacker can exploit this vulnerability by sending special constructed packets to obtain files in the device and upload files to some directories.

  • CVE-2019-9506HigAug 14, 2019
    risk 0.53cvss 8.1epss 0.03

    The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and…

  • CVE-2016-5234HigJun 13, 2016
    risk 0.53cvss 8.1epss 0.03

    Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconference devices with software before V500R002C00SPC100, when an unspecified service is enabled, allows remote attackers to execute…

  • CVE-2016-4087HigMay 23, 2016
    risk 0.53cvss 8.1epss 0.01

    Huawei S12700 switches with software before V200R008C00SPC500 and S5700 switches with software before V200R005SPH010, when the debug switch is enabled, allows remote attackers to cause a denial of service or execute arbitrary code via crafted DNS packets.

  • CVE-2016-3675HigApr 11, 2016
    risk 0.53cvss 8.1epss 0.01

    SQL injection vulnerability in Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to system databases.

  • CVE-2025-68958HigJan 14, 2026
    risk 0.52cvss 8.0epss 0.00

    Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68956HigJan 14, 2026
    risk 0.52cvss 8.0epss 0.00

    Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-68955HigJan 14, 2026
    risk 0.52cvss 8.0epss 0.00

    Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58310HigNov 28, 2025
    risk 0.52cvss 8.0epss 0.00

    Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-54634HigAug 6, 2025
    risk 0.52cvss 8.0epss 0.00

    Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-7300HigDec 26, 2024
    risk 0.52cvss 8.0epss 0.00

    Huawei Home Music System has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the music host file to be deleted or the file permission to be changed.(Vulnerability ID:HWPSIRT-2023-60613)

  • CVE-2022-48330HigJun 16, 2023
    risk 0.52cvss 8.0epss 0.00

    A Huawei sound box product has an out-of-bounds write vulnerability. Attackers can exploit this vulnerability to cause buffer overflow. Affected product versions include:FLMG-10 versions FLMG-10 10.0.1.0(H100SP22C00).

  • CVE-2020-9113HigOct 19, 2020
    risk 0.52cvss 8.0epss 0.00

    HUAWEI Mate 20 versions earlier than 10.0.0.188(C00E74R3P8) have a buffer overflow vulnerability in the Bluetooth module. Due to insufficient input validation, an unauthenticated attacker may craft Bluetooth messages after successful paring, causing buffer overflow. Successful…

  • CVE-2020-9067HigApr 2, 2020
    risk 0.52cvss 8.0epss 0.01

    There is a buffer overflow vulnerability in some Huawei products. The vulnerability can be exploited by an attacker to perform remote code execution on the affected products when the affected product functions as an optical line terminal (OLT). Affected product versions…

  • CVE-2017-8193HigNov 22, 2017
    risk 0.52cvss 8.0epss 0.01

    The FusionSphere OpenStack V100R006C00SPC102(NFV) has a command injection vulnerability. Due to the insufficient input validation on one port, an authenticated, local attacker may exploit the vulnerability to gain root privileges by sending message with malicious commands.

  • CVE-2017-2714HigNov 22, 2017
    risk 0.52cvss 8.0epss 0.01

    The GaussDB in FusionSphere OpenStack V100R005C10SPC705 and earlier versions has a buffer overflow vulnerability. An authenticated attacker on the LAN can exploit this vulnerability to execute arbitrary code or cause a denial of service (DoS) condition in the affected system.

  • CVE-2025-68968HigJan 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect the input function.

Page 7 of 48