Vulnerabilities in Huawei

1,367 results
Vexday analysis

Com 1.362 CVEs catalogadas, o portfólio de vulnerabilidades da Huawei apresenta volume expressivo, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV. O tipo de falha mais frequente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a viabilizar vazamento de informações ou condições de instabilidade em equipamentos de rede e sistemas embarcados. A CVE de maior pontuação EPSS no momento é CVE-2019-5285, com índice de 0,0166 — valor baixo em termos absolutos, mas que ainda merece atenção em ambientes onde o ativo afetado esteja exposto. A ausência de PoCs públicas conhecidas reduz a superfície de exploração imediata, mas os 57 registros de severidade crítica e as 47 CVEs surgidas nos últimos 90 dias indicam que a gestão contínua de patches permanece necessária.

CVE-2023-52546HIGHVulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affEPSS 0.2%CVE-2021-22458A component of the HarmonyOS has a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. Local attackers maEPSS 0.2%CVE-2024-45450MEDIUMPermission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.2%CVE-2022-44564HIGHHuawei Aslan Children's Watch has a path traversal vulnerability. Successful exploitation may allow attackers to access or modify protected EPSS 0.2%CVE-2026-28536CRITICALAuthentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnerability will affect iEPSS 0.2%CVE-2024-45442MEDIUMVulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability wEPSS 0.2%CVE-2022-44548MEDIUMThere is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may EPSS 0.2%CVE-2025-48906HIGHAuthentication bypass vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2024-56436MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2024-57962MEDIUMVulnerability of incomplete verification information in the VPN service module Impact: Successful exploitation of this vulnerability may affEPSS 0.2%CVE-2021-22420A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulneEPSS 0.2%CVE-2022-31762The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.EPSS 0.2%CVE-2021-22423A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflEPSS 0.2%CVE-2021-22418A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memEPSS 0.2%CVE-2021-22425A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating PrivileEPSS 0.2%CVE-2021-22422A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memEPSS 0.2%CVE-2023-41310Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause malicious apps to run coEPSS 0.2%CVE-2021-39986There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerabilEPSS 0.2%CVE-2021-39991There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerabilEPSS 0.2%CVE-2021-37115There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerabilEPSS 0.2%