Vulnerabilidades em Huawei

1.400 resultados
Análise Vexday

Com 1.362 CVEs catalogadas, o portfólio de vulnerabilidades da Huawei apresenta volume expressivo, embora a taxa de exploração ativa esteja abaixo da média geral do catálogo, com nenhuma entrada confirmada no CISA KEV. O tipo de falha mais frequente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a viabilizar vazamento de informações ou condições de instabilidade em equipamentos de rede e sistemas embarcados. A CVE de maior pontuação EPSS no momento é CVE-2019-5285, com índice de 0,0166 — valor baixo em termos absolutos, mas que ainda merece atenção em ambientes onde o ativo afetado esteja exposto. A ausência de PoCs públicas conhecidas reduz a superfície de exploração imediata, mas os 57 registros de severidade crítica e as 47 CVEs surgidas nos últimos 90 dias indicam que a gestão contínua de patches permanece necessária.

CVE-2022-44564HIGHHuawei Aslan Children's Watch has a path traversal vulnerability. Successful exploitation may allow attackers to access or modify protected EPSS 0.2%CVE-2024-45450MEDIUMPermission control vulnerability in the software update module. Impact: Successful exploitation of this vulnerability may affect service conEPSS 0.2%CVE-2024-45442MEDIUMVulnerability of permission verification for APIs in the DownloadProviderMain module Impact: Successful exploitation of this vulnerability wEPSS 0.2%CVE-2025-54609MEDIUMOut-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2025-54610MEDIUMOut-of-bounds access vulnerability in the audio codec module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2021-37115—There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerabilEPSS 0.2%CVE-2021-39986—There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerabilEPSS 0.2%CVE-2021-39991—There is an unauthorized rewriting vulnerability with the memory access management module on ACPU.Successful exploitation of this vulnerabilEPSS 0.2%CVE-2022-31762—The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.EPSS 0.2%CVE-2021-22425—A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating PrivileEPSS 0.2%CVE-2021-22423—A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflEPSS 0.2%CVE-2021-22418—A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memEPSS 0.2%CVE-2021-22420—A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulneEPSS 0.2%CVE-2021-22422—A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memEPSS 0.2%CVE-2023-41310—Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause malicious apps to run coEPSS 0.2%CVE-2025-53184MEDIUMNull pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function sEPSS 0.2%CVE-2025-53180MEDIUMNull pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function sEPSS 0.2%CVE-2025-53181MEDIUMNull pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function sEPSS 0.2%CVE-2025-53179MEDIUMNull pointer dereference vulnerability in the PDF preview module Impact: Successful exploitation of this vulnerability may affect function sEPSS 0.2%CVE-2024-54103MEDIUMVulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may affect service confidEPSS 0.2%