Huawei
huawei
2,339 CVEs • 1,953 products
Products (1,953)
Click to collapseToggle
Products (1,953)
Click to collapse
CVEs (2,339)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Stack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allows remote attackers to execute arbitrary code via malformed SNMPv3 requests. |
The Huawei viewpoint VP9610 and VP9620 units for the Huawei Video Conference system do not update the Session ID upon successful establishment of a login session, which allows remote authenticated users to hijack session...Show more |
1Huawei 3Quidway Service Process Unit Board S7700 Quidway Service Process Unit Board S9300Quidway Service Process Unit Board S9700Apr 29, 2026 Jun 20, 2013 N/A· v4 N/A· v3 3.5 LOW· v2 The firewall module on the Huawei Quidway Service Process Unit (SPU) board S7700, S9300, and S9700 on Huawei Campus Switch devices allows remote authenticated users to obtain sensitive information from the high-priority...Show more |
1Huawei 18Ar 18 1x Ar 18 2xAr 18 3x+15 moreApr 29, 2026 Jun 20, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches uses predictable Session ID v...Show more |
1Huawei 18Ar 18 1x Ar 18 2xAr 18 3x+15 moreApr 29, 2026 Jun 20, 2013 N/A· v4 N/A· v3 10.0 HIGH· v2 The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether...Show more |
1Huawei 18Ar 18 1x Ar 18 2xAr 18 3x+15 moreApr 29, 2026 Jun 20, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Stack-based buffer overflow in the HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500...Show more |
Buffer overflow in the back-end component in Huawei UTPS 1.0 allows local users to gain privileges via a long IDS_PLUGIN_NAME string in a plug-in configuration file. |
1Huawei 66Acu Ar 19/29/49Ar G3+63 moreApr 29, 2026 Jun 20, 2013 N/A· v4 N/A· v3 6.5 MEDIUM· v2 The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR...Show more |
2Hp Huawei675 Ma5200g 0150a1290150a12a+672 moreApr 29, 2026 Feb 1, 2013 N/A· v4 N/A· v3 3.5 LOW· v2 Certain HP Access Controller, Fabric Module, Firewall, Router, Switch, and UTM Appliance products; certain HP 3Com Access Controller, Router, and Switch products; certain HP H3C Access Controller, Firewall, Router, Switc...Show more |
The Huawei E585 device allows remote attackers to cause a denial of service (NULL pointer dereference and device outage) via crafted HTTP requests, as demonstrated by unspecified vulnerability-scanning software. |
Multiple directory traversal vulnerabilities on the Huawei E585 device allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the PATH_INFO of an sdcard/ request or (2) modify arbitrary files via a .. (...Show more |
The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to the LAN network. |
1Huawei 2Mt882 Modem Mt882 Modem FirmwareApr 23, 2026 Dec 4, 2009 N/A· v4 N/A· v3 4.7 MEDIUM· v2 rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically p...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in multiple scripts in Forms/ in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 allow remote attackers to inject arbitrary web script or HTML via the (1) Bac...Show more |
The Huawei D100 allows remote attackers to obtain sensitive information via a direct request to (1) lan_status_adv.asp, (2) wlan_basic_cfg.asp, or (3) lancfg.asp in en/, related to use of JavaScript to protect against re...Show more |
The default configuration of the Wi-Fi component on the Huawei D100 does not use encryption, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. |
The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-dependent attackers to obtain sensitive information by (1) reading a cookie file, by (2) sniffing the ne...Show more |
The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a default password of admin for the admin account in the telnet interface; which m...Show more |
The Huawei Versatile Routing Platform 1.43 2500E-003 firmware on the Quidway R1600 Router, and possibly other models, allows remote attackers to cause a denial of service (device crash) via a long show arp command. |