Vulnerabilities > Huawei

DATE CVE VULNERABILITY TITLE RISK
2016-06-14 CVE-2016-5366 Improper Access Control vulnerability in Huawei Honor Ws851 Firmware 1.1.21.1
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to modify configuration data via vectors related to a "file injection vulnerability," aka HWPSIRT-2016-05052.
network
low complexity
huawei CWE-284
7.5
2016-06-14 CVE-2016-5365 Permissions, Privileges, and Access Controls vulnerability in Huawei Honor Ws851 Firmware 1.1.21.1
Stack-based buffer overflow in Huawei Honor WS851 routers with software 1.1.21.1 and earlier allows remote attackers to execute arbitrary commands with root privileges via unspecified vectors, aka HWPSIRT-2016-05051.
network
low complexity
huawei CWE-264
critical
9.8
2016-06-13 CVE-2016-5234 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Rse6500 Firmware and Vp9600 Series Firmware
Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconference devices with software before V500R002C00SPC100, when an unspecified service is enabled, allows remote attackers to execute arbitrary code via a crafted packet, aka HWPSIRT-2016-05054.
network
high complexity
huawei CWE-119
8.1
2016-06-13 CVE-2016-4005 Cryptographic Issues vulnerability in Huawei Hilink APP 3.19.1
The Huawei Hilink App application before 3.19.2 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
local
low complexity
huawei CWE-310
5.5
2016-06-13 CVE-2016-3677 Insufficient Verification of Data Authenticity vulnerability in Huawei Hilink APP and Wear APP
The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
network
low complexity
huawei CWE-345
6.5
2016-06-10 CVE-2016-5233 Information Exposure vulnerability in Huawei Mate 8 Firmware
Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 before NXT-DL00C17B182, and NXT-TL00 before NXT-TL00C01B182 allow remote base stations to obtain sensitive subscriber signal strength information via vectors involving improper security status verification, aka HWPSIRT-2015-12007.
network
high complexity
huawei CWE-200
3.7
2016-05-26 CVE-2016-3681 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Mate 8 Firmware
Buffer overflow in the Wi-Fi driver in Huawei Mate 8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to cause a denial of service (crash) or possibly gain privileges via a crafted application, aka HWPSIRT-2016-03021.
local
low complexity
huawei CWE-119
7.8
2016-05-26 CVE-2016-3680 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei Mate 8 Firmware
Buffer overflow in the Wi-Fi driver in Huawei Mate 8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to cause a denial of service (crash) or possibly gain privileges via a crafted application, aka HWPSIRT-2016-03020.
local
low complexity
huawei CWE-119
7.8
2016-05-25 CVE-2016-4575 Cross-site Scripting vulnerability in Huawei products
Cross-site scripting (XSS) vulnerability in the email APP in Huawei PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92 before AL10C92B211; ATH smartphones with software AL00C00 before AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361, and UL00C00 before UL00C00B361; CherryPlus smartphones with software TL00C00 before TL00C00B553, UL00C00 before UL00C00B553, and TL00MC01 before TL00MC01B553; and RIO smartphones with software AL00C00 before AL00C00B360 allows remote attackers to inject arbitrary web script or HTML via an email message.
network
low complexity
huawei CWE-79
6.1
2016-05-23 CVE-2016-4577 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Huawei products
Buffer overflow in the Smart DNS functionality in the Huawei NGFW Module and Secospace USG6300, USG6500, USG6600, and USG9500 firewalls with software before V500R001C20SPC100 allows remote attackers to cause a denial of service or execute arbitrary code via a crafted packet, related to "illegitimate parameters."
high complexity
huawei CWE-119
7.5