Vulnerabilities (CVE)

Filtered by vendor Huawei Subscribe
Total 2282 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-2271 1 Huawei 1 D100 2025-04-09 10.0 HIGH N/A
The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a default password of admin for the admin account in the telnet interface; which makes it easier for remote attackers to obtain access.
CVE-2009-4196 1 Huawei 1 Mt882 V100t002b020 Arg-t 2025-04-09 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in multiple scripts in Forms/ in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 allow remote attackers to inject arbitrary web script or HTML via the (1) BackButton parameter to error_1; (2) wzConnFlag parameter to fresh_pppoe_1; (3) diag_pppindex_argen and (4) DiagStartFlag parameters to rpDiag_argen_1; (5) wzdmz_active and (6) wzdmzHostIP parameters to rpNATdmz_argen_1; (7) wzVIRTUALSVR_endPort, (8) wzVIRTUALSVR_endPortLocal, (9) wzVIRTUALSVR_IndexFlag, (10) wzVIRTUALSVR_localIP, (11) wzVIRTUALSVR_startPort, and (12) wzVIRTUALSVR_startPortLocal parameters to rpNATvirsvr_argen_1; (13) Connect_DialFlag, (14) Connect_DialHidden, and (15) Connect_Flag parameters to rpStatus_argen_1; (16) Telephone_select, and (17) wzFirstFlag parameters to rpwizard_1; and (18) wzConnectFlag parameter to rpwizPppoe_1.
CVE-2009-2274 1 Huawei 1 D100 2025-04-09 7.8 HIGH N/A
The Huawei D100 allows remote attackers to obtain sensitive information via a direct request to (1) lan_status_adv.asp, (2) wlan_basic_cfg.asp, or (3) lancfg.asp in en/, related to use of JavaScript to protect against reading file contents.
CVE-2021-33658 2 Huawei, Openatom 2 Atune, Openeuler 2025-04-02 4.6 MEDIUM 7.8 HIGH
atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate the local privilege or modify any file. Authentication is not forcibly enabled in the default configuration.
CVE-2024-30417 1 Huawei 2 Emui, Harmonyos 2025-03-29 N/A 7.5 HIGH
Path traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-52378 1 Huawei 2 Emui, Harmonyos 2025-03-29 N/A 9.8 CRITICAL
Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.
CVE-2023-52540 1 Huawei 2 Emui, Harmonyos 2025-03-28 N/A 7.5 HIGH
Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-30413 1 Huawei 2 Emui, Harmonyos 2025-03-28 N/A 7.5 HIGH
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2024-27895 1 Huawei 1 Harmonyos 2025-03-28 N/A 7.5 HIGH
Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
CVE-2023-52546 1 Huawei 2 Emui, Harmonyos 2025-03-28 N/A 7.5 HIGH
Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-52715 1 Huawei 1 Harmonyos 2025-03-28 N/A 7.5 HIGH
The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2023-52386 1 Huawei 2 Emui, Harmonyos 2025-03-27 N/A 7.5 HIGH
Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2023-52359 1 Huawei 2 Emui, Harmonyos 2025-03-27 N/A 7.5 HIGH
Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2023-52373 1 Huawei 2 Emui, Harmonyos 2025-03-27 N/A 7.5 HIGH
Vulnerability of permission verification in the content sharing pop-up module.Successful exploitation of this vulnerability may cause unauthorized file sharing.
CVE-2023-52363 1 Huawei 2 Emui, Harmonyos 2025-03-27 N/A 5.3 MEDIUM
Vulnerability of defects introduced in the design process in the Control Panel module.Successful exploitation of this vulnerability may cause app processes to be started by mistake.
CVE-2023-52387 1 Huawei 2 Emui, Harmonyos 2025-03-27 N/A 7.5 HIGH
Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-52375 1 Huawei 2 Emui, Harmonyos 2025-03-26 N/A 7.5 HIGH
Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability.
CVE-2023-52369 1 Huawei 2 Emui, Harmonyos 2025-03-25 N/A 9.1 CRITICAL
Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.
CVE-2023-52538 1 Huawei 2 Emui, Harmonyos 2025-03-25 N/A 9.1 CRITICAL
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2022-48299 1 Huawei 2 Emui, Harmonyos 2025-03-25 N/A 7.5 HIGH
The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.