← Back

Huawei

huawei

2,339 CVEs • 1,953 products

Products (1,953)

Click to collapse
Toggle
Harmonyos
harmonyos
Emui
emui
Magic Ui
magic_ui
Te60 Firmware
te60_firmware
Te30 Firmware
te30_firmware
Te50 Firmware
te50_firmware
Te40 Firmware
te40_firmware
P30 Firmware
p30_firmware
P8 Firmware
p8_firmware
Fusioncompute
fusioncompute
P9 Firmware
p9_firmware
Uma
uma
Manageone
manageone
P20 Firmware
p20_firmware
P10 Firmware
p10_firmware
Hisuite
hisuite

CVEs (2,339)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
1P8 Smartphone Firmware
May 6, 2026
Aug 2, 2016
N/A· v4
7.3 HIGH· v3
9.3 HIGH· v2
Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vul...Show more
Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6193.Show less
1Huawei
5Cloudengine 12800 Firmware
Cx600 FirmwareNe40e Firmware+2 more
May 6, 2026
Aug 2, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with software before V800R006SPH018; and CloudEngine devices 12800 with softw...Show more
Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with software before V800R006SPH018; and CloudEngine devices 12800 with software before V100R003SPH010 and V100R005 before V100R005SPH006 allow remote attackers with control plane access to cause a denial of service or execute arbitrary code via a crafted packet.Show less
1Huawei
1Hisuite
May 6, 2026
Jul 13, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Huawei HiSuite before 4.0.4.204_ove (Out of China) and before 4.0.4.301 (China) use a weak ACL (FILE_WRITE_DATA for BUILTIN\Users) for the HiSuite service directory, which allows local users to gain SYSTEM privileges via...Show more
Huawei HiSuite before 4.0.4.204_ove (Out of China) and before 4.0.4.301 (China) use a weak ACL (FILE_WRITE_DATA for BUILTIN\Users) for the HiSuite service directory, which allows local users to gain SYSTEM privileges via a Trojan horse (1) SspiCli.dll or (2) USERENV.dll file or possibly other unspecified DLL files.Show less
1Huawei
1Public Cloud Solution
May 6, 2026
Jul 12, 2016
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the volume backup service module in Huawei Public Cloud Solution before 1.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
1Huawei
1Ar3200 Firmware
May 6, 2026
Jun 30, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Memory leak in Huawei AR3200 before V200R007C00SPC900 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted Multiprotocol Label Switching (MPLS) packets.
1Huawei
1Mate 8 Firmware
May 6, 2026
Jun 30, 2016
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
Buffer overflow in Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to cause a denial of service (system crash)...Show more
Buffer overflow in Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to cause a denial of service (system crash) via a crafted app.Show less
1Huawei
1Mate 8 Firmware
May 6, 2026
Jun 30, 2016
N/A· v4
7.8 HIGH· v3
5.0 MEDIUM· v2
Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and delete user data via a crafted...Show more
Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and delete user data via a crafted app.Show less
1Huawei
1Mate 8 Firmware
May 6, 2026
Jun 30, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and control partial module function...Show more
Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and control partial module functions via a crafted app.Show less
1Huawei
1Hisuite
May 6, 2026
Jun 30, 2016
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
Huawei HiSuite (In China) before 4.0.4.301 and (Out of China) before 4.0.4.204_ove allows remote attackers to install arbitrary apps on a connected phone via unspecified vectors.
1Huawei
1Fusioncompute
May 6, 2026
Jun 30, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Huawei FusionCompute before V100R005C10SPC700 allows remote authenticated users to cause a denial of service (resource consumption) via a large number of crafted packets.
1Huawei
1Fusioninsight Hd
May 6, 2026
Jun 24, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Huawei FusionInsight HD before V100R002C60SPC200 allows local users to gain root privileges via unspecified vectors.
1Huawei
1Ocean Stor Firmware
May 6, 2026
Jun 24, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Huawei OceanStor 5300 V3, 5500 V3, 5600 V3, 5800 V3, 6800 V3, 18800 V3, and 18500 V3 before V300R003C10 sends the plaintext session token in the HTTP header, which allows remote attackers to conduct replay attacks and ob...Show more
Huawei OceanStor 5300 V3, 5500 V3, 5600 V3, 5800 V3, 6800 V3, 18800 V3, and 18500 V3 before V300R003C10 sends the plaintext session token in the HTTP header, which allows remote attackers to conduct replay attacks and obtain sensitive information by sniffing the network.Show less
1Huawei
1Huawei Firmware
May 6, 2026
Jun 24, 2016
N/A· v4
5.9 MEDIUM· v3
7.1 HIGH· v2
Memory leak in Huawei IPS Module, NGFW Module, NIP6300, NIP6600, and Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 V500R001C00 before V500R001C20SPC100, when in hot standby networking where two devices a...Show more
Memory leak in Huawei IPS Module, NGFW Module, NIP6300, NIP6600, and Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 V500R001C00 before V500R001C20SPC100, when in hot standby networking where two devices are not directly connected, allows remote attackers to cause a denial of service (memory consumption and reboot) via a crafted packet.Show less
1Huawei
1Honor Ws851 Firmware
May 6, 2026
Jun 14, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors, aka HWPSIRT-2016-05053.
1Huawei
1Honor Ws851 Firmware
May 6, 2026
Jun 14, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to modify configuration data via vectors related to a "file injection vulnerability," aka HWPSIRT-2016-05052.
1Huawei
1Honor Ws851 Firmware
May 6, 2026
Jun 14, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Stack-based buffer overflow in Huawei Honor WS851 routers with software 1.1.21.1 and earlier allows remote attackers to execute arbitrary commands with root privileges via unspecified vectors, aka HWPSIRT-2016-05051.
1Huawei
2Rse6500 Firmware
Vp9600 Series Firmware
May 6, 2026
Jun 13, 2016
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconference devices with software before V500R002C00SPC100, when an unspecified...Show more
Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconference devices with software before V500R002C00SPC100, when an unspecified service is enabled, allows remote attackers to execute arbitrary code via a crafted packet, aka HWPSIRT-2016-05054.Show less
1Huawei
1Hilink App
May 6, 2026
Jun 13, 2016
N/A· v4
5.5 MEDIUM· v3
7.5 HIGH· v2
The Huawei Hilink App application before 3.19.2 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
1Huawei
2Hilink App
Wear App
May 6, 2026
Jun 13, 2016
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
1Huawei
1Mate 8 Firmware
May 6, 2026
Jun 10, 2016
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 before NXT-DL00C17B182, and NXT-TL00 before NXT-TL00C01B182 allow remote base stations to obtain sensitiv...Show more
Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 before NXT-DL00C17B182, and NXT-TL00 before NXT-TL00C01B182 allow remote base stations to obtain sensitive subscriber signal strength information via vectors involving improper security status verification, aka HWPSIRT-2015-12007.Show less