← Back

Huawei

huawei

2,339 CVEs • 1,953 products

Products (1,953)

Click to collapse
Toggle
Harmonyos
harmonyos
Emui
emui
Magic Ui
magic_ui
Te60 Firmware
te60_firmware
Te30 Firmware
te30_firmware
Te50 Firmware
te50_firmware
Te40 Firmware
te40_firmware
P30 Firmware
p30_firmware
P8 Firmware
p8_firmware
Fusioncompute
fusioncompute
P9 Firmware
p9_firmware
Uma
uma
Manageone
manageone
P20 Firmware
p20_firmware
P10 Firmware
p10_firmware
Hisuite
hisuite

CVEs (2,339)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
1P9 Plus Firmware
May 13, 2026
Nov 22, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The soundtrigger driver in P9 Plus smart phones with software versions earlier than VIE-AL10BC00B353 has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the appl...Show more
The soundtrigger driver in P9 Plus smart phones with software versions earlier than VIE-AL10BC00B353 has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the application can start multiple threads and try to free specific memory, which could triggers double free and causes a system crash or arbitrary code execution.Show less
1Huawei
1Hedex Lite
May 13, 2026
Nov 22, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HedEx Earlier than V200R006C00 versions have the stored cross-site scripting (XSS) vulnerability. Attackers can exploit the vulnerability to plant malicious scripts into the configuration file to interrupt the services o...Show more
HedEx Earlier than V200R006C00 versions have the stored cross-site scripting (XSS) vulnerability. Attackers can exploit the vulnerability to plant malicious scripts into the configuration file to interrupt the services of legitimate users.Show less
1Huawei
1Hedex Lite
May 13, 2026
Nov 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a website containing malicious scripts which may tamper with configurations and...Show more
HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a website containing malicious scripts which may tamper with configurations and interrupt normal services.Show less
1Huawei
1Hedex Lite
May 13, 2026
Nov 22, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
HedEx Earlier than V200R006C00 versions has a dynamic link library (DLL) hijacking vulnerability due to calling the DDL file by accessing a relative path. An attacker could exploit this vulnerability to tamper with the D...Show more
HedEx Earlier than V200R006C00 versions has a dynamic link library (DLL) hijacking vulnerability due to calling the DDL file by accessing a relative path. An attacker could exploit this vulnerability to tamper with the DLL file, leading to DLL hijacking.Show less
1Huawei
1Hedex Lite
May 13, 2026
Nov 22, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
HedEx Earlier than V200R006C00 versions has an arbitrary file download vulnerability. An attacker could exploit it to download arbitrary files on a target device to cause information leak.
1Huawei
1Fusionsphere Openstack
May 13, 2026
Nov 22, 2017
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the...Show more
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.Show less
1Huawei
1Fusionsphere Openstack
May 13, 2026
Nov 22, 2017
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the...Show more
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.Show less
1Huawei
1Neteco
May 13, 2026
Nov 22, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Huawei iManager NetEco with software V600R008C00 and V600R008C10 has a command injection vulnerability. An authenticated, remote attacker could exploit this vulnerability to send malicious packets to a target device. Suc...Show more
Huawei iManager NetEco with software V600R008C00 and V600R008C10 has a command injection vulnerability. An authenticated, remote attacker could exploit this vulnerability to send malicious packets to a target device. Successful exploit could enable a low privileged user to execute commands that a high privileged user could execute, causing the files to be tampered with or deleted.Show less
1Huawei
1Fusionsphere Openstack
May 13, 2026
Nov 22, 2017
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the...Show more
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.Show less
1Huawei
1Fusionsphere Openstack
May 13, 2026
Nov 22, 2017
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the...Show more
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.Show less
1Huawei
1Uma
May 13, 2026
Nov 22, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.
1Huawei
1Uma
May 13, 2026
Nov 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these v...Show more
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.Show less
1Huawei
1Uma
May 13, 2026
Nov 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these v...Show more
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.Show less
1Huawei
1Uma
May 13, 2026
Nov 22, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.
1Huawei
1Uma
May 13, 2026
Nov 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilitie...Show more
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.Show less
1Huawei
1Uma
May 13, 2026
Nov 22, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.
1Huawei
1Uma
May 13, 2026
Nov 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilitie...Show more
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.Show less
1Huawei
1Uma
May 13, 2026
Nov 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilitie...Show more
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.Show less
1Huawei
1Uma
May 13, 2026
Nov 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilitie...Show more
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.Show less
1Huawei
1Uma
May 13, 2026
Nov 22, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.