Записи Huawei
2 340 опубликованных записей вендора huawei.
Профиль для исследователя
- Попали в KEV
- 3 · 0,1 %
- С эксплойтом
- 4 · 0,2 %
- Pre-auth RCE
- 51
- С записью об исправлении
- 0,3 %
- Медиана: публикация → KEV
- 754 дн.
Повторяющиеся классы
- CWE-20 Improper Input Validation230
- CWE-125 Out-of-bounds Read147
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor110
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer109
- CWE-287 Improper Authentication87
- CWE-787 Out-of-bounds Write87
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
2 340 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2019-0708Готовый эксплойт | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attackermicrosoft · windows 7 · CWE-416 | Критическая9,8 | KEV | 100,0 % | 16 мая 2019 г. |
83Срочно | CVE-2019-2215Готовый эксплойт | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.google · android · CWE-416 | Высокая7,8 | KEV | 72,1 % | 11 окт. 2019 г. |
64На этой неделе | CVE-2017-14491Proof of concept | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code viathekelleys · dnsmasq · CWE-787 | Критическая9,8 | — | 84,9 % | 3 окт. 2017 г. |
61На этой неделе | CVE-2020-0069Готовый эксплойт | In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization agoogle · android · CWE-787 | Высокая7,8 | KEV | 1,4 % | 10 мар. 2020 г. |
58В плане | CVE-2017-17215Proof of concept | Huawei HG532 with some customized versions has a remote code execution vulnerability.huawei · hg532 firmware · CWE-20 | Высокая8,8 | — | 78,3 % | 20 мар. 2018 г. |
47В плане | CVE-2020-8840Proof of concept | FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyedifasterxml · jackson-databind · CWE-502 | Критическая9,8 | — | 26,6 % | 10 февр. 2020 г. |
41В плане | CVE-2016-8276Эксплойта нет | Buffer overflow in the Point-to-Point Protocol over Ethernet (PPPoE) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified securithuawei · usg2100 · CWE-119 | Критическая9,8 | — | 5,6 % | 3 окт. 2016 г. |
41В плане | CVE-2017-3216Эксплойта нет | WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remotegreenpacket · ox350 firmware · CWE-306 | Критическая9,8 | — | 5,2 % | 19 июн. 2017 г. |
41В плане | CVE-2014-9134Эксплойта нет | Unrestricted file upload vulnerability in Huawei Honor Cube Wireless Router WS860s before V100R001C02B222 allows remote attackers to executehuawei · honor cube wireless router ws860s firewall | Критическая10,0 | — | 2,5 % | 3 дек. 2014 г. |
41В плане | CVE-2012-6570Эксплойта нет | The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S30huawei · ar 18-1x · CWE-119 | Критическая10,0 | — | 1,7 % | 20 июн. 2013 г. |
40В плане | CVE-2016-6206Эксплойта нет | Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code vhuawei · ar3200 firmware · CWE-20 | Критическая9,8 | — | 3,8 % | 24 мар. 2017 г. |
40В плане | CVE-2016-7109Эксплойта нет | Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characterhuawei · uma · CWE-94 | Критическая9,8 | — | 3,5 % | 7 сент. 2016 г. |
40В плане | CVE-2016-6178Эксплойта нет | Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devichuawei · ne5000e firmware · CWE-20 | Критическая9,8 | — | 3,0 % | 2 авг. 2016 г. |
40В плане | CVE-2013-2612Эксплойта нет | Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with huawei · e587 firmware · CWE-78 | Критическая9,8 | — | 3,0 % | 27 янв. 2020 г. |
40В плане | CVE-2016-7110Эксплойта нет | Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characterhuawei · uma · CWE-94 | Критическая9,8 | — | 2,7 % | 7 сент. 2016 г. |
40В плане | CVE-2017-2738Эксплойта нет | VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability.huawei · vcm5010 firmware · CWE-287 | Критическая9,8 | — | 2,7 % | 22 нояб. 2017 г. |
40В плане | CVE-2016-4576Эксплойта нет | Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, Shuawei · nip6300 · CWE-119 | Критическая9,8 | — | 2,4 % | 23 мая 2016 г. |
40В плане | CVE-2016-6825Эксплойта нет | Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPhuawei · rh1288 v3 server firmware · CWE-285 | Критическая9,8 | — | 2,1 % | 7 сент. 2016 г. |
40В плане | CVE-2015-7841Эксплойта нет | The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software huawei · fusionserver ch121 v3 · CWE-77 | Критическая9,8 | — | 2,1 % | 2 окт. 2017 г. |
40В плане | CVE-2016-5365Эксплойта нет | Stack-based buffer overflow in Huawei Honor WS851 routers with software 1.1.21.1 and earlier allows remote attackers to execute arbitrary cohuawei · honor ws851 · CWE-264 | Критическая9,8 | — | 2,1 % | 14 июн. 2016 г. |
40В плане | CVE-2015-4629Эксплойта нет | Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN/PUK authentication,huawei · e5756s firmware · CWE-264 | Критическая9,8 | — | 1,7 % | 7 сент. 2017 г. |
40В плане | CVE-2009-2271Эксплойта нет | The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a huawei · d100 · CWE-255 | Критическая10,0 | — | 1,3 % | 1 июл. 2009 г. |
40В плане | CVE-2026-34865Эксплойта нет | Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confihuawei · harmonyos · CWE-122 | Критическая10,0 | — | 0,4 % | 13 апр. 2026 г. |
39Наблюдать | CVE-2019-19398Эксплойта нет | M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability.huawei · m5 lite 10 firmware · CWE-20 | Критическая9,8 | — | 1,4 % | 26 дек. 2019 г. |
39Наблюдать | CVE-2021-37095Эксплойта нет | There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remothuawei · harmonyos · CWE-190 | Критическая9,8 | — | 1,4 % | 7 дек. 2021 г. |
- CVE-2019-070899Срочно
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows 716 мая 2019 г.
- CVE-2019-221583Срочно
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 72 %google · android11 окт. 2019 г.
- CVE-2017-1449164На этой неделе
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via
КритическаяCVSS 9,8Proof of conceptEPSS 85 %thekelleys · dnsmasq3 окт. 2017 г.
- CVE-2020-006961На этой неделе
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization a
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 1 %google · android10 мар. 2020 г.
- CVE-2017-1721558В плане
Huawei HG532 with some customized versions has a remote code execution vulnerability.
ВысокаяCVSS 8,8Proof of conceptEPSS 78 %huawei · hg532 firmware20 мар. 2018 г.
- CVE-2020-884047В плане
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyedi
КритическаяCVSS 9,8Proof of conceptEPSS 27 %fasterxml · jackson-databind10 февр. 2020 г.
- CVE-2016-827641В плане
Buffer overflow in the Point-to-Point Protocol over Ethernet (PPPoE) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified securit
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %huawei · usg21003 окт. 2016 г.
- CVE-2017-321641В плане
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %greenpacket · ox350 firmware19 июн. 2017 г.
- CVE-2014-913441В плане
Unrestricted file upload vulnerability in Huawei Honor Cube Wireless Router WS860s before V100R001C02B222 allows remote attackers to execute
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %huawei · honor cube wireless router ws860s firewall3 дек. 2014 г.
- CVE-2012-657041В плане
The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S30
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %huawei · ar 18-1x20 июн. 2013 г.
- CVE-2016-620640В плане
Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code v
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %huawei · ar3200 firmware24 мар. 2017 г.
- CVE-2016-710940В плане
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special character
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %huawei · uma7 сент. 2016 г.
- CVE-2016-617840В плане
Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devic
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %huawei · ne5000e firmware2 авг. 2016 г.
- CVE-2013-261240В плане
Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %huawei · e587 firmware27 янв. 2020 г.
- CVE-2016-711040В плане
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special character
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %huawei · uma7 сент. 2016 г.
- CVE-2017-273840В плане
VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %huawei · vcm5010 firmware22 нояб. 2017 г.
- CVE-2016-457640В плане
Buffer overflow in the Application Specific Packet Filtering (ASPF) functionality in the Huawei IPS Module, NGFW Module, NIP6300, NIP6600, S
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %huawei · nip630023 мая 2016 г.
- CVE-2016-682540В плане
Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SP
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %huawei · rh1288 v3 server firmware7 сент. 2016 г.
- CVE-2015-784140В плане
The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %huawei · fusionserver ch121 v32 окт. 2017 г.
- CVE-2016-536540В плане
Stack-based buffer overflow in Huawei Honor WS851 routers with software 1.1.21.1 and earlier allows remote attackers to execute arbitrary co
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %huawei · honor ws85114 июн. 2016 г.
- CVE-2015-462940В плане
Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN/PUK authentication,
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %huawei · e5756s firmware7 сент. 2017 г.
- CVE-2009-227140В плане
The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %huawei · d1001 июл. 2009 г.
- CVE-2026-3486540В плане
Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect availability and confi
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %huawei · harmonyos13 апр. 2026 г.
- CVE-2019-1939839Наблюдать
M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %huawei · m5 lite 10 firmware26 дек. 2019 г.
- CVE-2021-3709539Наблюдать
There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remot
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %huawei · harmonyos7 дек. 2021 г.