Vulnerabilities (CVE)

Filtered by vendor Huawei Subscribe
Total 2332 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-4196 1 Huawei 1 Mt882 V100t002b020 Arg-t 2026-04-23 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in multiple scripts in Forms/ in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 allow remote attackers to inject arbitrary web script or HTML via the (1) BackButton parameter to error_1; (2) wzConnFlag parameter to fresh_pppoe_1; (3) diag_pppindex_argen and (4) DiagStartFlag parameters to rpDiag_argen_1; (5) wzdmz_active and (6) wzdmzHostIP parameters to rpNATdmz_argen_1; (7) wzVIRTUALSVR_endPort, (8) wzVIRTUALSVR_endPortLocal, (9) wzVIRTUALSVR_IndexFlag, (10) wzVIRTUALSVR_localIP, (11) wzVIRTUALSVR_startPort, and (12) wzVIRTUALSVR_startPortLocal parameters to rpNATvirsvr_argen_1; (13) Connect_DialFlag, (14) Connect_DialHidden, and (15) Connect_Flag parameters to rpStatus_argen_1; (16) Telephone_select, and (17) wzFirstFlag parameters to rpwizard_1; and (18) wzConnectFlag parameter to rpwizPppoe_1.
CVE-2009-4197 1 Huawei 3 Mt882 Modem, Mt882 Modem Firmware, Mt882 V100t002b020 Arg-t 2026-04-23 4.7 MEDIUM N/A
rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically proximate attackers to obtain the password from web browsers that support autocomplete.
CVE-2007-0488 1 Huawei 1 Versatile Routing Platform 2026-04-23 5.0 MEDIUM N/A
The Huawei Versatile Routing Platform 1.43 2500E-003 firmware on the Quidway R1600 Router, and possibly other models, allows remote attackers to cause a denial of service (device crash) via a long show arp command.
CVE-2009-2274 1 Huawei 1 D100 2026-04-23 7.8 HIGH N/A
The Huawei D100 allows remote attackers to obtain sensitive information via a direct request to (1) lan_status_adv.asp, (2) wlan_basic_cfg.asp, or (3) lancfg.asp in en/, related to use of JavaScript to protect against reading file contents.
CVE-2009-2272 1 Huawei 2 D100, D100 Firmware 2026-04-23 5.0 MEDIUM 7.5 HIGH
The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-dependent attackers to obtain sensitive information by (1) reading a cookie file, by (2) sniffing the network for HTTP headers, and possibly by using unspecified other vectors.
CVE-2009-2271 1 Huawei 1 D100 2026-04-23 10.0 HIGH N/A
The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a default password of admin for the admin account in the telnet interface; which makes it easier for remote attackers to obtain access.
CVE-2009-2273 1 Huawei 2 D100, D100 Firmware 2026-04-23 5.0 MEDIUM N/A
The default configuration of the Wi-Fi component on the Huawei D100 does not use encryption, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
CVE-2026-34866 1 Huawei 1 Harmonyos 2026-04-17 N/A 5.1 MEDIUM
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2026-34865 1 Huawei 1 Harmonyos 2026-04-17 N/A 9.1 CRITICAL
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2026-34855 1 Huawei 2 Emui, Harmonyos 2026-04-17 N/A 5.7 MEDIUM
Out-of-bounds write vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2026-34867 1 Huawei 1 Harmonyos 2026-04-17 N/A 5.6 MEDIUM
Double free vulnerability in the multi-mode input system. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-34850 1 Huawei 1 Harmonyos 2026-04-16 N/A 1.9 LOW
Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-34851 1 Huawei 1 Harmonyos 2026-04-16 N/A 2.2 LOW
Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-34852 1 Huawei 1 Harmonyos 2026-04-16 N/A 6.1 MEDIUM
Stack overflow vulnerability in the media platform. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-34853 1 Huawei 2 Emui, Harmonyos 2026-04-16 N/A 7.7 HIGH
Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-34856 1 Huawei 1 Harmonyos 2026-04-16 N/A 7.3 HIGH
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-34860 1 Huawei 1 Harmonyos 2026-04-16 N/A 4.1 MEDIUM
Access control vulnerability in the memo module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2026-34854 1 Huawei 2 Emui, Harmonyos 2026-04-15 N/A 5.7 MEDIUM
UAF vulnerability in the kernel module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
CVE-2026-34857 1 Huawei 1 Harmonyos 2026-04-15 N/A 4.7 MEDIUM
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-34858 1 Huawei 1 Harmonyos 2026-04-15 N/A 4.1 MEDIUM
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.